Hello, this is Ryuta Hamamoto from TIMEWELL.
America's first comprehensive AI law died before it took effect. Colorado's AI Act (CAIA, SB 24-205), signed by Governor Polis on May 17, 2024 and watched by AI-regulation observers worldwide, never reached its original February 1, 2026 effective date or the delayed June 30 date. On May 12, 2026 the Colorado legislature itself passed SB 26-189 and repealed CAIA.
A law that lived and died in 24 months is unusual in regulatory history. Writing it off as "America's first comprehensive AI law was a failure" is still too quick. The architecture CAIA designed—high-risk AI eight categories, developer/deployer dual responsibility, NIST AI RMF safe harbor—alongside successor ADMT, Connecticut SB 5, and the EU AI Act, will keep shaping Japanese companies' AI governance design.
What happened, why, and what remains. In that order.
TL;DR
- CAIA was repealed by SB 26-189 on May 12, 2026 and replaced with an ADMT (Automated Decision-Making Technology) framework; new effective date January 1, 2027
- Triggers: (1) industry pushback, (2) extraterritorial issues, (3) Governor Polis's reservations, (4) xAI lawsuit + DOJ intervention
- Even so, CAIA's eight high-risk categories × developer/deployer × impact assessment × NIST AI RMF safe harbor remains industry common language
- Japanese companies should implement this architecture, not CAIA as statute—reusable for EU AI Act, ADMT, Connecticut SB 5, and other state rules
What happened on May 12, 2026: a 24-month timeline
| Date | Event |
|---|---|
| May 17, 2024 | Governor Polis signs SB 24-205 (first US comprehensive AI law) |
| June 2024 | Governor issues unusual statement of "implementation concerns" |
| August 28, 2025 | SB 25B-004 signed: effective date delayed from Feb 1, 2026 to June 30 |
| December 11, 2025 | President Trump signs "December order"; directs AI Litigation Task Force |
| April 9, 2026 | xAI sues in Colorado federal court (First Amendment, Commerce Clause, equal protection) |
| April 24, 2026 | DOJ intervenes in xAI suit (first state-AI-law intervention under EO 14365) |
| April 27, 2026 | Federal magistrate stays CAIA (joint motion to stay) |
| May 12, 2026 | Colorado legislature passes SB 26-189—repeals CAIA, replaces with ADMT |
| January 1, 2027 | ADMT scheduled to take effect |
The political mechanics were three-layered. State: industry and the governor seeking relief. Federal: Trump-era push for state-law preemption. Judicial: constitutional challenge by xAI. Three pressures at once crushed CAIA.
I read this as a case study for regulation designers. If you pre-empt with advanced, comprehensive rules without target-industry buy-in, political dismantling before effective date is possible. The EU AI Act pushing back its high-risk AI application dates under the Digital Omnibus (Regulation (EU) 2026/1744) looks like a smaller version of the same structure.
AI Security training, taken seriously
A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.
What original CAIA required
Without the original text, industry resistance is hard to understand.
Scope: eight high-risk AI categories. Education (admissions, scholarships, evaluation). Employment (hiring, promotion, termination, compensation). Finance/credit (credit scores, loan underwriting). Essential government services (benefits, welfare). Healthcare (diagnosis, treatment prioritization, insurance benefits). Housing (tenant screening, eviction). Insurance (underwriting, rates). Legal services (legal tech). All domains that touch daily life.
Roles: developer and deployer dual structure.
- Developers: reasonable care to foresee and prevent algorithmic discrimination; technical documentation for deployers; notify Colorado AG and deployers within 90 days of discovery of material discrimination
- Deployers: reasonable care to prevent algorithmic discrimination; risk management program (NIST AI RMF or equivalent); impact assessments (before use, annual refresh, within 90 days of material change); consumer disclosure and human review rights
Fines: up to $20,000 per violation, Colorado AG exclusive enforcement, no private right of action. Treated as Colorado Consumer Protection Act violations.
Safe harbor: NIST AI RMF compliance as affirmative defense. Strong design thinking retained in successor ADMT.
Read this far and "not a bad design" is a fair reaction. Compliance communities often called CAIA America's most mature AI regulation. The problem was less the substance than implementation cost and federal–state friction.
Why dismantled before effective date: four factors
First: industry cost concerns. HR tech (Workday, SAP SuccessFactors, ADP, HireVue), finance/credit (Hudson Cook and peers), healthcare AI vendors argued that building Colorado-only data cards, impact assessments, and notice flows did not pay. Patchwork cost across similar-but-different state rules was the core complaint.
Second: extraterritorial application. CAIA applied to those "doing business in Colorado," but serving a single Colorado resident from New York or Texas raised Dormant Commerce Clause issues. That is where xAI's commerce claims landed.
Third: Governor Polis's own reservations. From signing day he publicly preferred national uniformity over state patchwork and supported delay. Unusual politics: the governor who signed the law hollowing it out.
Fourth: federal December order and DOJ intervention. The December 11, 2025 executive order and January 9, 2026 AI Litigation Task Force signaled aggressive federal intervention against state AI laws. xAI's April 9 filing, DOJ intervention April 24, and court stay April 27 closed in three weeks.
Simultaneity was fatal. Industry alone might have been managed over time. Governor reservations alone might have been overridden by the legislature. Federal intervention alone might have met a counter-EO. All four together made CAIA structurally unsustainable.
Federal–state friction is covered in US federal AI policy 2026. This dismantling is also the first clear case of federal tactics working against a state AI law.
How SB 26-189 ADMT differs
SB 26-189 redesigns into a narrower, implementable ADMT (Automated Decision-Making Technology) framework. Three points:
Point 1: Scope narrowed to automated decision-making technology. CAIA covered AI systems broadly; ADMT focuses on technology that automates or assists human decisions. Generative-AI recommendations alone are generally out; machine-final credit decisions are in. That sharply reduces HR tech assessment surface.
Point 2: Transparency-first; discrimination prevention secondary. CAIA's core of algorithmic discrimination prevention moves back. Transparency disclosure and consumer notice move forward, tracing to the Colorado AI Policy Work Group's March 17, 2026 transparency-heavy alternative framework.
Point 3: Effective date January 1, 2027. Extra time lets industry build to ADMT. Ironically, "repeal and replace" was more convenient for industry than "delay and keep original text." That is the May 2026 industry mood I hear.
Learning from the EU AI Act and "failure to induce compliance"
CAIA aimed to be a state-level EU AI Act. Eight high-risk categories nearly match Annex III. Dual developer/deployer responsibility, impact assessments, consumer disclosure. Structure is strikingly similar.
The fatal difference was penalty magnitude.
| Item | CAIA | EU AI Act |
|---|---|---|
| High-risk AI violation | Up to $20,000 per violation | Up to €15M or 3% of global revenue |
| Prohibited AI violation | (no parallel clause) | Up to €35M or 7% of global revenue |
| Enforcement | Colorado AG only | Member-state authorities + EU AI Office |
| Private right of action | None | Member-state dependent |
$20,000 max rarely clears a global firm's ROI bar for compliance investment. Industry drifted toward "paying $20k is cheaper than running annual assessments." Weak incentives to comply, which hardened resistance.
The EU AI Act uses fine weight to make rules non-ignorable. In that sense it succeeds. CAIA's paradoxical failure: good design, fines too light for serious compliance. Another design lesson.
Five implementation pointers for Japanese companies
"CAIA is dead, so ignore it" is wrong. For executives and legal I organize five points:
1. Use CAIA architecture as the internal baseline. Eight categories × developer/deployer × impact assessment × NIST AI RMF safe harbor is compatible with EU AI Act, ADMT, Connecticut SB 5, and other state ADMT rules. Keep reading it as a design reference, not a dead statute.
2. Put multi-state AI law clauses in HR tech vendor contracts. With Workday, SAP SuccessFactors, and peers, require vendor technical documentation for state AI laws and notice duties on discrimination findings. Colorado repealed CAIA; Texas, New York, Connecticut will still impose analogues.
3. Build one impact-assessment template integrating CAIA, EU AI Act, and NIST AI RMF. One template covering multiple regimes minimizes lateral rollout cost across states.
4. Standardize consumer notice + human review language. Templates in English and Japanese: "We use AI"; "After an adverse decision you may request data correction and human review." Reusable for EU AI Act Article 13, ADMT, and state ADMT rules.
5. Prepare AG-notification workflows. Ability to notify a state AG within 90 days of discovering discrimination. CAIA is gone; ADMT, Connecticut, California keep similar duties. Design discovery → legal → communications → AG notice now.
Where this sits in WARP SECURITY
TIMEWELL's WARP SECURITY uses the Colorado CAIA dismantling as workshop material for "laws that pass but never take effect."
For executives: tabletop drills on where to plant compliance investment, at enactment, delay, lawsuit, and repeal, and how to rewrite vendor contracts. CAIA is past; ADMT, Connecticut SB 5, and Texas TRAIGA will force the same judgments.
For operators: lab sessions mapping CAIA architecture (eight categories × dual responsibility × NIST AI RMF) onto real products: HR, credit, healthcare, housing. Writing impact assessments live.
One of five simulated-incident drills covers first response when a state AI law requires AG notice within 90 days. Role-play of legal, communications, and executive boundaries.
The EU AI Act timeline: what actually starts on August 2, 2026
This article argued that fines too light mean rules go unfollowed. The opposite pole, the EU AI Act (Regulation (EU) 2024/1689), has August 2, 2026 as its general date of application. That does not mean every obligation begins that day, and the confusion is worth clearing up article by article.
What applies from August 2, 2026: Chapter IV transparency obligations (Article 50), Chapter III Section 5 (Articles 40–49: harmonised standards, conformity assessment, CE marking, registration), Chapter VI, Chapters VIII–XI, and the European Commission's power to fine general-purpose AI (GPAI) providers (Article 101). Commission supervision and enforcement over GPAI providers take effect on that date; GPAI-related sanctions reach €15 million or 3% of worldwide turnover, and breaches of the prohibited practices in Article 5 reach €35 million or 7% (Regulatory framework on AI (European Commission)).
High-risk AI substantive obligations are not on that date. The Digital Omnibus is now law as Regulation (EU) 2026/1744 (adopted July 8, 2026; published as OJ L 2026/1744 on July 24, 2026; in force July 27, 2026). Under it, Chapter III Sections 1–3 apply to Annex III high-risk AI (Article 6(2)) from December 2, 2027, and to Annex I product-embedded high-risk AI (Article 6(1)) from August 2, 2028. The authorised representative duty (Article 22), value-chain responsibilities (Article 25), deployer obligations (Article 26), and the fundamental rights impact assessment (Article 27) start with the Annex III date as well. The transitional rule for systems already placed on the market (Article 111(2)) was also rewritten: it bites only where significant changes in their designs are made on or after the Chapter III application date, rather than on a fixed calendar date.
The staged dates are:
| Date of application | Scope |
|---|---|
| February 2, 2025 | Chapter I (general provisions, definitions, Article 4 AI literacy); Chapter II (Article 5 prohibited practices) |
| August 2, 2025 | Chapter III Section 4 (notifying authorities), Chapter V (GPAI models), Chapter VII (governance), Chapter XII (penalties, Articles 99–100), Article 78 — Article 101 excluded |
| July 27, 2026 | Regulation 2026/1744 enters into force; AI Act Articles 102–110 (amendments to other legislation) start applying |
| August 2, 2026 (general date of application) | Chapter IV (Article 50 transparency), Chapter III Section 5 (Articles 40–49), Chapter VI, Chapters VIII–XI, Article 101 (Commission GPAI fining power) |
| December 2, 2026 | New prohibited practices (Article 5(1)(ba), (bb) and Article 5(1a), (1b)); plus Article 111(4): providers of synthetic-content generators placed on the market before August 2, 2026 must comply with Article 50(2) by this date |
| August 2, 2027 | Article 111(3): compliance deadline for GPAI models placed on the market before August 2, 2025 |
| December 2, 2027 | Chapter III Sections 1–3 apply to Annex III high-risk AI (Article 6(2)) |
| August 2, 2028 | Same sections apply to Annex I high-risk AI (Article 6(1), product-embedded) |
Note that Article 50 itself still applies from August 2, 2026. Regulation 2026/1744 amended only Article 50(7) (codes of practice); the substantive duties in Article 50(1)–(6) are unchanged. What happens on December 2, 2026 is the start of the new prohibitions plus the transitional deadline for existing systems — nothing more.
CAIA's pre-effective dismantling versus the EU's staged widening of scope reinforces the view that penalty magnitude sets compliance incentives. For Japanese implementation themes, also see Personal Information Protection Act 2026 amendment.
Summary
- America's first comprehensive AI law CAIA (SB 24-205) was repealed on May 12, 2026 without ever taking effect
- Dismantling resulted from industry pushback, extraterritorial issues, gubernatorial reservations, and federal DOJ intervention acting together
- CAIA's eight high-risk categories × developer/deployer × impact assessment × NIST AI RMF safe harbor remains industry common language
- Reusable as regulatory literacy for ADMT (Jan 2027), Connecticut SB 5, and the EU AI Act
- Fines too light mean rules go unfollowed. The EU AI Act comparison is the design lesson
Asked whether learning a dead law is worthwhile, I answer yes without hesitation. Laws that stay in force and laws that were well designed are not the same set. CAIA was well designed, and that is why industry learned how to resist it effectively. For AI-regulation governance, it is one of the most re-readable cases we have.
References
- Colorado AI Act Repealed: What SB 26-189 Means - Ropes & Gray
- Navigating Colorado's AI Act and Its Repeal - Wilson Sonsini
- Colorado AI Policy Work Group Final Recommendations (March 2026)
- xAI v. Weiser - DOJ Complaint in Intervention
- Comparing Colorado's AI Act to the EU AI Act - White & Case
- NIST AI Risk Management Framework






