Field Notes
Colorado Repealed Its AI Act — What Actually Governs Your AI Receptionist Now
Quick answer: The Colorado AI Act (SB 24-205) was repealed on May 14, 2026 — before it ever took effect. The law that replaced it, SB 26-189, establishes a lighter automated decision-making technology (ADMT) disclosure framework that doesn’t take effect until January 1, 2027. What actually governs your AI voice receptionist right now is federal TCPA — the Telephone Consumer Protection Act — along with A2P 10DLC registration for any SMS your system sends. If you’ve been holding off on deploying an AI receptionist because of Colorado compliance fear, that fear was based on a law that no longer exists.
Most of the web hasn’t caught up to this yet. You can still find articles from late 2024 and early 2025 warning operators to prepare for Colorado’s sweeping AI liability framework — duty of care, risk-management programs, algorithmic impact assessments — framing it as a compliance cliff edge arriving in mid-2026. That cliff got quietly demolished. The operative question for a small business operator deploying an AI receptionist today is not “am I ready for Colorado’s AI Act?” It’s “do I have my TCPA consent language right, and is my SMS infrastructure registered?” Different question. Shorter answer.
What SB 24-205 Said — and Why It Got Repealed
Colorado’s original AI Act, signed in May 2024, was ambitious in scope. It imposed a statutory “duty of care” on developers and deployers of high-risk AI systems, defined roughly as any AI making consequential decisions affecting a consumer’s access to housing, employment, education, healthcare, financial services, or similar categories. Deployers would have been required to conduct algorithmic impact assessments, implement risk-management programs, and provide consumers with meaningful notice and opt-out rights.
The effective date was originally February 1, 2026, then pushed to June 30, 2026. Governor Polis signed the repeal — SB 26-189 — on May 14, 2026, before either deadline arrived. The repeal wasn’t a stealth move; Polis had signaled reservations about the original law even as he signed it in 2024. Business community pushback and legitimate concerns about regulatory fragmentation across states accelerated the decision.
What replaced it is substantially narrower.
What SB 26-189 Actually Says (Effective January 1, 2027)
The replacement law is still a real regulation — don’t read the repeal as a green light to deploy AI recklessly. But the character of the obligations changed fundamentally.
SB 26-189 is structured around disclosure and consumer rights for automated decision-making technology, not around the duty-of-care and impact-assessment framework that defined the original act. The key shifts:
- No duty of care. The new law does not impose liability based on a developer or deployer’s failure to exercise “reasonable care” in the design or deployment of high-risk AI.
- No mandatory impact assessments. The algorithmic audit and risk-management-program requirements that defined SB 24-205 are gone.
- Disclosure-centric. The new framework focuses on telling consumers that an automated decision-making system is being used and giving them pathways to contest or understand those decisions.
- Effective January 1, 2027. Nothing in SB 26-189 is operative today. You have time to read it and get current.
For most small business operators running an AI voice receptionist, a chatbot, or an AI-assisted SMS follow-up sequence, the honest assessment is: neither version of the Colorado law was primarily aimed at you. High-risk AI under the original act was squarely focused on decisions affecting employment, credit, healthcare access, and similar high-stakes categories. An AI that answers your after-hours calls and texts back a booking confirmation link is not that kind of system.
What Actually Governs Your AI Receptionist Right Now
This is the part that hasn’t changed and won’t. Federal TCPA compliance is not a Colorado-specific issue, not a 2027 problem — it’s the live operational constraint on any AI voice or SMS deployment today.
The three pillars:
1. AI disclosure on voice calls. The FCC’s 2024 declaratory ruling confirmed that AI-generated voice calls fall within TCPA’s existing consent and disclosure framework. If your AI receptionist is making outbound calls — or even returning calls with a voice agent that could be mistaken for a human — there are disclosure obligations. The standard approach is a brief upfront disclosure: “This call may be handled by an automated assistant.” Short. Honest. Required.
2. A2P 10DLC registration for SMS. Any SMS sent by a business through application-to-person channels — which includes every AI-triggered text your receptionist sends — must be registered through the 10DLC system with your carrier. Unregistered traffic gets filtered. There is no grace period, no grandfathering, and no “we just launched” exception. If you’re sending AI-triggered texts and you’re not registered, your messages are being blocked and you don’t know it. Our AI receptionist SMS compliance post covers the A2P registration process step by step — it’s worth reading before you send your first automated text.
3. TCPA opt-in consent for marketing SMS. There is a meaningful legal distinction between a transactional text (booking confirmation, appointment reminder) and a marketing text (promotional offer, follow-up sequence). Marketing texts require prior express written consent. “Written” in this context includes a checkbox on a web form — but that checkbox has to be specific, unconditional, and not bundled with a general terms-of-service agreement. Get the consent language right at intake. Fix it later is harder than building it correctly the first time.
Why Most “Colorado AI Act Compliance” Content Online Is Now Wrong
The repeal was signed May 14, 2026. Content published before that date — and a lot of it was published in late 2024 through spring 2026 — describes a regulatory world that no longer exists. The guidance to conduct impact assessments, appoint AI accountability officers, and build duty-of-care documentation into your AI deployments is advice aimed at a law that was repealed.
This creates a specific problem: operators who find that content today will do compliance work that doesn’t match current law, while possibly missing the TCPA obligations that actually apply. The wrong work, skipping the right work.
The broader AI regulatory landscape is genuinely evolving, and state-level frameworks will continue to emerge. But the correct posture for a small business operator in mid-2026 is to anchor compliance on federal TCPA — which is active and enforced — and to monitor state developments (Colorado’s SB 26-189, California’s ongoing AI legislative activity) as they move toward effective dates, not before.
A Practical Compliance Checklist for AI Voice and SMS Deployment
This is the checklist we run for every AI receptionist deployment through our AI demo and implementation service. It’s not a legal opinion — it’s an operator’s orientation to the decisions that actually matter.
- Voice disclosure language confirmed. Any AI voice agent must disclose its automated nature at or near the start of the call.
- A2P 10DLC registration completed. Business, campaign, and use-case registered with your carrier or aggregator before the first text goes out.
- TCPA-compliant opt-in at intake. Web form, booking widget, or point-of-sale capture includes specific, unconditional consent language for marketing SMS. Transactional texts (confirmations, reminders) run on a separate track.
- Opt-out honored immediately. Any STOP reply or verbal opt-out during a call terminates that contact’s SMS enrollment and must be honored within ten business days under TCPA — we build this into the CRM workflow so it’s automatic.
- Single conversation thread per customer. Four-channel systems (voice, SMS, chat, reputation) need to write to one CRM record per contact, or you’re flying blind on who has opted out of what.
- Accessible web chat. If your AI receptionist has a chat widget on your site, that widget must meet WCAG 2.1 AA standards. We cover the accessibility baseline in detail at WCAG 2.1 AA without excuses — the same standard applies to the chat surface, not just the rest of the page.
- Colorado SB 26-189 calendar reminder. Set a Q3 2026 reminder to review the new ADMT disclosure framework for January 1, 2027 applicability to your deployment.
When You Actually Need a Lawyer
Not every compliance question requires a retainer. But some do.
You need an attorney when: you’re deploying AI that makes or materially influences decisions about creditworthiness, employment eligibility, insurance pricing, or healthcare access. You need an attorney when: a consumer has sent a cease-and-desist or you’ve received a TCPA demand letter. You need an attorney when: you’re building a co-marketing or referral structure around your AI system that involves multiple parties (the RESPA parallels here are worth noting — we covered that territory in the preferred lender lead forms post).
For a restaurant deploying an AI host to answer after-hours calls, or a fitness studio using an AI assistant to catch the leads that ring through during a 6am class, or a realtor running an AI-powered text follow-up sequence — the compliance surface is narrower. TCPA consent language, A2P registration, voice disclosure. Those are attorney-informed decisions that don’t require ongoing legal engagement. Build it right once, then operate it confidently.
The AI receptionist category is genuinely moving fast, and the compliance environment will continue to tighten over the next two to three years. The operators who build clean consent infrastructure now — not because a specific law forces them to, but because it’s the durable way to build — will have less to fix when the next round of state-level frameworks land.
If you want to see what a compliant, four-channel AI receptionist deployment actually looks like before you commit to building one, the right first move is a live demo call — not a slide deck. Book through /services/ai-demo/ and we’ll call you and walk through voice, SMS, chat, and reputation as a working system, with the compliance logic visible. Either it fits your operation, or we’ll tell you honestly what would fit better. If you have not yet decided between AI and a human answering service at all, compare the virtual receptionist options first — the compliance burden differs by category, not just by vendor.
About the author — Mike Clack is the co-founder of Backyard Bougie, Inc. and leads technology strategy, AI system deployment, and compliance architecture for the studio’s small business clients across hospitality, real estate, fitness, and professional services.