I have never filed a public comment on anything.
Not on a zoning notice, not on a federal rule, not on one of the dockets I have quoted here all year. My theory was that by the time a rule reaches the comment stage the decisions are made, and comment is the paperwork of consent. Then I spent a week inside one Colorado file and had the sequence handed back to me backwards. That legislature passed a statute full of words that do not yet mean anything — materially influence, meaningful, commercially reasonable — and gave the meaning to a rulemaking. The comment window is not the ceremony after the law. Here it is the law.
I owe you a completion, too. In June I wrote that Colorado had repealed the toughest AI law in America before it could bite. True — but I never followed the calendar to the date the fight had pointed at, June 30, 2026.
Nothing happened. That turns out to be the story.
June 30 arrived, and there was nothing left to enforce
Colorado's 2024 law was meant to start policing high-risk AI on February 1, 2026. A special session in August 2025 produced a postponement of the initial enforcement date to June 30. That October, Governor Jared Polis convened a second working group to fix the statute first — 19 voting members, and pointedly no lawmakers and no lobbyists.
Then two things happened in the spring, and neither was a vote.
On April 9, 2026, xAI sued Colorado Attorney General Philip J. Weiser in federal court. On April 27, on the parties' own joint motion, a magistrate judge ordered that Weiser "shall not initiate enforcement", investigations included, for alleged violations of the 2024 act; Bloomberg Law reported the law would not be enforced until a federal court ruled on a forthcoming injunction motion. Resist inflating that: the stay came by agreement, not on the merits. No court has held the law unconstitutional, no injunction has been decided, and the case is ongoing.
Then, on May 14, Polis signed Senate Bill 26-189, which repeals and reenacts those provisions. The Colorado Sun described two years of debate ending with little fanfare in a measure watering down — and once again delaying the first-in-the-nation statute, pushing its start from June to January 2027 — a law that, in the Sun's words, "has yet to go into effect." Skadden was blunter: Colorado repealed its landmark act before it took effect, eliminating the duty of care on algorithmic discrimination, the impact assessments and the risk-management program with it.
So, the plain accounting: the 2024 statute has regulated nothing and disciplined nobody, and its replacement reaches only decisions made on or after January 1, 2027 — a date that holds, as Davis Polk notes, only provided the Colorado Attorney General completes the requisite rulemaking process by that date. Two laws, thirty months, zero enforcement.
The line in the new law that has your name on it
The enrolled text lists the domains the rewrite covers, and one of them is essential government services and public benefits, including eligibility and renewal determinations. Read that last clause twice. Not only whether you get in. Whether you stay in.
Be precise about the delta, because the easy version is wrong. The 2024 statute already reached an essential government service. What is new is the widening — public benefits spelled out beside government services, and eligibility and renewal named. A small change with a large picture behind it: somebody was thinking about the letter that arrives in year three saying the hours are cut.
That letter has a history here. The ACLU's Jay Stanley has described an Idaho case where families found their annual Medicaid assistance suddenly cut by twenty or thirty percent; asked how the number was produced, the state answered we can't tell you that, it's a trade secret. A court ordered disclosure — then held the formula so bad it was unconstitutional. In Arkansas, an algorithm called Resource Utilization Groups set people's care needs; after a federal court found the state had violated due process requirements, it suspended care reductions for several months and rewrote its notices.
The Center for Democracy & Technology's survey has the pattern in a clause: sold as efficiency and fraud control, rolled out with little public debate, incredibly difficult to understand once underway. That is the population Colorado's covered domain now names.
What you actually get, and what you have to ask for
So what does the statute hand a person on the wrong end?
A letter. If a covered system materially influences a consequential decision that goes against you, the deployer has thirty days to provide "a plain language description of the consequential decision and the role the covered ADMT played." That is more than most Americans get today.
Then human review — and here careful writers overstate. The text does not guarantee a person looks again. The consumer may request, and the deployer shall then provide an opportunity for meaningful human review and reconsideration — "to the extent commercially reasonable." You have to ask; the duty is capped by commercial reasonableness; and none of it requires correcting "opinions, predictions, scores, or protected evaluations" — a fairly complete description of what these systems produce.
Stefani Langehennig of the University of Denver's Daniels College of Business wrote the honest sentence about that trade: the company has no obligation to audit the system that produced the decision, so the burden shifts from the institution deploying the technology to the individual affected by it.
And if the letter never comes, you do not sue. The act creates no new private right of action; those provisions are enforceable exclusively by the Attorney General, as deceptive trade practices carrying fines of up to $20,000 per violation, after sixty days' notice and a chance to cure, except for knowing or repeat violations — a right that itself sunsets on January 1, 2030.
Here is the question I could not get answered, and I looked hard. The covered domain is public benefits, but the duty-bearer is a "deployer," meaning "a person doing business in Colorado." The enrolled bill never uses "governmental," "political subdivision," "state agency" or "public entity," never defines "person," and enforces through a consumer-protection statute. Every law-firm guide I found reads it as a rulebook for businesses; none asks whether a county human-services department is a deployer. The subject matter is covered. Who answers for it is unsettled.
The part still being written closes on October 26
This is why I stopped dismissing comment windows.
On August 11, 2026, the Colorado Department of Law filed proposed rules to clarify and implement Senate Bill 26-189 and a companion chatbot law. Written comment runs through October 26, 2026, with a formal hearing that day.
What the drafts would add is not cosmetic. The disclosure would have to reach you by at least two methods; the deployer would have to confirm receipt of your request within ten days and complete meaningful human review within 45 days. They also try to pin down the phrase the statute turns on: a de minimis factor has only a trifling, trivial or incidental impact on the outcome. And your reviewer should be independent of the original decision-maker whenever feasible. Qualifiers in draft rules are where the next five years live.
These are proposals; they bind nobody. Which is the point: for a few more weeks the statute's meaning is still soft. There is a clock at the other end, too: under the April order, xAI agreed to move for a preliminary injunction within 28 days after final adoption of rulemaking implementing the 2024 act or any legislation that could replace or amend it. The rulemaking is both the moment the law acquires meaning and the starting gun for the fight over it.
Before you call this cowardice
Polis's office called the framework a nation-leading model built with developers, users and consumers. On the same page, Robert Lindgren of the Colorado AFL-CIO called the bill a good first step — then said what he still wanted: "it's that you test these systems ahead of time to ensure that they do not discriminate." A good first step, not a betrayal. Keep both halves.
The compliance objection was real too. Trade associations warned the act could create heavy administrative burdens for startups; the Independence Institute, a free market think tank in Denver, reported technology coalitions calling it "deeply flawed." Nor was it a backroom job: testimony emphasized the six months and hundreds of hours the working group put in, while advocates argued for a private right of action, given the Attorney General's office's limited resources, and lost in public.
Now the part that pushes hardest against my own thesis: Colorado's retreat is not the country's direction. Reviewing the year, Epstein Becker Green found states moving to a second generation of requirements — auditing, reporting, and affirmative anti-discrimination obligations making employers demonstrate their systems do not produce discriminatory outcomes, not merely disclose that AI was used. The same review calls SB 26-189 one of the most significant pieces of employment AI legislation enacted this cycle. One of. Not the. Colorado is a data point, not a verdict.
France asked this exact question in 2016, aimed the answer at benefits, and lost in court anyway
One country already ran Colorado's experiment on precisely this population, and the judgments are in a public database.
France's Digital Republic Act of October 7, 2016 obliged the administration to say explicitly when a decision rests on algorithmic processing, and to explain it on request. What that explanation contains is startling next to Colorado's. Per the French government's own guidance, whoever asks is owed the degree and mode of the algorithm's contribution, the data used and their sources, the operations performed, and les paramètres de traitement et leur pondération, appliqués à la situation de l'intéressé — the parameters and their weighting, applied to your own situation. Colorado promises a description of the role the system played. France promises the weights, as applied to you.
Above that sits a constitutional layer. Ruling on June 12, 2018, the Conseil constitutionnel held that a public body must be able to explain in detail and in an intelligible format how the processing was applied to the individual — then wrote the sentence with no American counterpart: where an algorithm's operating principles cannot be communicated without breaching a protected secret, "no individual decision shall be made on the exclusive basis of this algorithm." Since July 1, 2020, a decision taken with no human intervention at all must carry the explicit mention à peine de nullité — though scope that carefully, since nullity reaches fully automated processing, not every algorithm-assisted decision. Refused an explanation, you go to the CADA, an independent administrative authority that issues opinions on refusals — an address Colorado gives no one.
So France wrote the stronger right. Here is what it bought.
Four researchers read every judgment invoking that article between June 2022 and August 2024 — 163 — and titled their study an ineffectiveness. 161 of the 163 cases concerned social benefits payments, mostly challenges to departmental councils and benefit funds demanding repayment of overpaid support. The courts reject the argument systematically; thirty-seven judgments say expressly that the required mention "n'est pas une condition de légalité de la décision, mais une simple formalité" — not a condition of the decision's legality, merely a formality. One trial court held otherwise in December 2022, over a housing-benefit clawback; the study calls it isolated.
The mechanism is the portable part. French courts almost always separate the ciblage algorithmique — the targeting that pulled your file — from the décision finale, the human-signed demand for repayment. The algorithm did not decide; it selected you for the human who did. That is the joint Colorado's "materially influence" test is walking toward, and why the definition of de minimis in a draft rule is not a technicality.
The scoring itself is now before France's highest administrative court. Fifteen civil society groups challenged the family-benefit fund's algorithm in October 2024; La Quadrature du Net says it analyzes the personal data of more than 32 million people living in benefit-receiving households each month, with low income, unemployment and disability benefits among the factors raising what Amnesty International France calls un score de suspicion; by January 2026 the coalition had grown to twenty-five. Those are claimants' characterizations in a pending case: there is no ruling as of this writing, and the campaigners' line that the discrimination has been "confirmed" rests on an advisory opinion, not a judicial finding.
None of which argues for writing nothing. It argues about which words carry.
Now push the calendar to 2029
Picture a renewal in Colorado, three winters from now. Your mother's in-home care hours drop from forty a week to twenty-seven.
The system works — that is what makes it worth imagining. Within thirty days a letter arrives, and a second copy by another channel, describing in plain language the role the automated system played. You request review, get an acknowledgment in ten days and a decision in forty-five. Your reviewer is meant to be independent of the original decision-maker "whenever feasible"; this month it was not, so she is not. She reads the same score you cannot see, and affirms it.
Then you ask who is responsible. The contractor says it only flagged the file — a caseworker made the final call, so the model did not materially influence anything; its impact was trifling, incidental, de minimis. With no private right of action, you write to the Attorney General, whose office must give the contractor sixty days to cure.
Nobody broke a rule in that scene. Everyone complied. And it is plausible rather than paranoid because French courts have almost systematically accepted the targeting-versus-decision split, in a case law overwhelmingly about benefits.
What the people who study this are saying
The free-market critique deserves its own words. The R Street Institute, in a February 2026 paper by Adam Thierer and Logan Kolas, put Colorado's 2024 act at the top of its "AI Terrible Ten" and described what state and local governments have built as a regulatory briar patch of fear-based laws, proposing a national framework instead. That is an advocacy ranking, not a neutral audit — though the complaint about fifty regimes is one I share.
From the other direction, the objection is not that disclosure is bad but that it is thin. Michele Gilman's guide for poverty lawyers at Data & Society makes the distributional point: automated systems decide things about our lives, and people of low socioeconomic status often bear the brunt of the harms these systems cause. And Hannah Bloch-Wehba, writing for the Knight First Amendment Institute, named what a notice regime is for — instead of transparency as a tool of democratic participation, we get a minimal obligation to ensure that individuals know how and when decisions are made about them. A precise description of the statute Colorado now has.
What does this mean for you?
If you live in Colorado, the comment window is open until October 26. Write about the ordinary case — a renewal, a denial, a form — and name the words that need a floor: materially influence, meaningful human review, commercially reasonable.
Ask the question nobody has answered: does "person" include a county? The covered domain names public benefits; the duty-bearer is a person doing business in Colorado. If the rulemaking does not close that gap, nothing will.
From January 1, 2027, ask in writing — the letter is owed, the human is not. Review exists only if you request it. Ask for the role the system played, and know the ceiling: nothing requires anyone to correct an opinion, a prediction or a score.
Do not wait to become a plaintiff. There is no private right of action, so the complaint you send the Attorney General is the entire enforcement mechanism.
If you live elsewhere, read your own state's bill for one distinction. Does it impose a duty on the company, or only a disclosure to you? And does its word for the regulated party reach a public agency?
The lesson, as I see it
Two Colorado laws now exist that have never governed anyone: one repealed before its deadline arrived, the other waiting for a deadline that has not come. In thirty months of the loudest state AI fight in America, the only thing enforced is a pause the parties agreed to.
I would not read that as futility, though, and no longer as theater. The signing ceremony was never the moment. The moment is a comment file in Denver that closes on October 26, where somebody is deciding whether "materially influence" means what a contractor says it means once a human has signed the letter. France has shown what happens when that question is left to be settled afterward, in court: a strong right, 163 judgments, and benefits claimants told over and over that the algorithm had merely picked them.
My vote? Treat the rulemaking as the legislature. Show up while the words are still soft — and if you have ever assumed, as I did, that public comment is a suggestion box, consider that in Colorado this fall it is the last place a sentence about your benefits can still be changed.
The HAIA Foundation exists for a plain idea: when a machine helps decide something that changes your life, a human should still be answerable for it. If you would rather have the next rule read while it can still be changed, subscribe — reading early is the whole job.





