Executive Summary
- Automated Decision-Making Technology Act (ADMTA), effective January 1, 2027, eliminates the exemption that lets banks and credit unions skip direct compliance simply by being examined by a prudential regulator.
- The act also hands banks a shortcut: an existing Regulation B adverse action notice can, under the Colorado Attorney General’s proposed rules, already satisfy the new disclosure requirement for the same decision.
- That shortcut only works if the letter can name the AI system, its data sources, and a designated reviewer, and retain that record for three years.
- Many banks may not be able to produce that content today. 49 percent of banks and 59 percent of credit unions have deployed generative AI , while only 13 percent have reached the highest AI governance maturity tier.
- Closing this gap is an execution-layer question, not a legal one.
The Exemption Is Gone, and the Shortcut That Replaced It Has a Catch
Colorado’s new AI disclosure law does not create a paperwork requirement banks lack today. It removes one they used to lean on. Banks and credit unions examined by a prudential regulator no longer get automatic compliance.
In exchange, the law hands them a genuine shortcut: an adverse action notice they already send can satisfy the new disclosure rule outright.
The practical catch is easy to miss: the shortcut only works if that existing notice can document what drove the decision.
What ADMTA Actually Changed
Colorado did not amend its AI Act. It repealed the Colorado AI Act (CAIA) before that law took effect and replaced it with the Automated Decision-Making Technology Act (ADMTA), signed May 14, 2026 and effective January 1, 2027, contingent on the attorney general completing required rulemaking by that date.
The rewrite followed sustained industry opposition and narrowed the law considerably, dropping the CAIA’s algorithmic discrimination duty, impact assessments, and risk management program requirements in favor of a transparency regime.
ADMTA covers seven domains, including lending and financial services, and a “consequential decision” is not limited to approvals and denials. It includes differentiated pricing, cost, or other material terms that materially limit, delay, deny, or alter a consumer’s access to a financial service.
For example, a loan priced worse because of an automated risk score is in scope, not only a loan that gets declined.
The law also carves out specific activities: cybersecurity, AML and counter-terrorist financing controls, sanctions compliance, and fraud prevention, including identity verification.
An IVR identity check sits outside ADMTA’s scope for that reason. There is no blanket GLBA exemption, so the scoring, pricing, and underwriting-recommendation tools banks use in offering financial products remain in scope even though identity and fraud tools do not.
The Reg B Shortcut Only Works If the Letter Can Prove What’s Inside
A financial institution that already sends Regulation B adverse action notices, and Fair Credit Reporting Act notices where applicable, satisfies ADMTA’s disclosure requirement for that same decision.
Within 30 days of an adverse outcome, that notice has to carry:
- a plain-language description of the decision and the AI system’s role,
- instructions for the consumer to get more information, and
- an explanation of their rights: access to the personal data used, correction of inaccurate data, and meaningful human review by a reviewer the bank has specifically designated and trained, with authority to override the outcome.
Developers and deployers must both retain the system version and data used for at least three years. That is a lower bar than a separate filing.
It’s also the piece most institutions are least likely to already have covered.
Three gaps are typical.
Current Reg B letters name the reason for denial, not the specific AI system or version that materially influenced it.
No single system logs which data source, core banking or third-party, contributed to a decision and retains that record for three years.
And there is no designated, trained reviewer with logged authority to override an outcome on request. An agent can escalate a complaint; few contact centers can show that an authorized person reviewed and could have reversed a specific decision.
This lands on institutions already deep into AI adoption. 49 percent of banks and 59 percent of credit unions have deployed generative AI, and agentic AI is now discussed at the board level at more than half of institutions.
63 percent of bank employees use AI weekly, yet only 13 percent of banks have reached the highest AI governance maturity tier, and 87 percent have significant room to strengthen their frameworks. (Deloitte, “Banking on Trust: AI Governance for Growth, Resilience and Scale,” 2026).
The shortcut exists on paper at nearly every bank. The operational record needed to use it typically doesn’t.
This Is an Execution-Layer Gap, Not a Legal One
Integration answers whether system A can share data with system B. It does not answer what happens with that data, in what sequence, under what permission, or who is accountable for each step.
ADMTA’s shortcut asks for exactly that second layer: which AI system and data source materially influenced a specific decision, retained for three years, produced inside a 30-day window.
Connectivity moves data. CCIP controls execution. Connectivity alone does not record that a specific retrieval happened before a specific validation, which happened before a specific pricing or underwriting output.
A bank can have every system connected and still be unable to name, for one customer’s adverse outcome, which AI system and data source drove it. That is the gap between having the shortcut available and being able to use it.
How CCIP Fills In the Letter
NovelVox CCIP sits between the CCaaS platform, the AI layer, and core banking systems, including Jack Henry, Fiserv, and FIS, Corelation (KeyStone), governing how every action is retrieved, validated, and executed during a live interaction.
CCIP connects through two protocols, REST APIs for real-time data exchange and an MCP Server for context-aware AI agents acting across systems in a multi-step workflow, both feeding the same governed execution layer. CCIP is one product, not two.
Every retrieval from a named core banking system, every automated score or pricing output, and every write-back action, such as updating an application status or triggering a payment arrangement, executes in a defined sequence with validations and business rules built to the interaction’s requirements.
Each step is captured in an audit trail: which system was called, what data it returned, which AI system and version generated the output, and what action followed.
| Download Case Study: How a Leading Credit Union is Unifying Agent and Self-Service Banking with NovelVox |
That is the kind of system-and-source record the Reg B disclosure is designed to capture. It gives an existing adverse action letter the underlying evidence to support an ADMTA disclosure, instead of requiring a separate compliance project.
Role-based access routes human-review requests to the designated, authorized reviewer, and the same sequence log meets the three-year retention requirement without a parallel record-keeping system.
For banks looking at what this looks like end to end across a member-facing stack, not just at the point of AI disclosure, Connected to Compete: An Integration-First Guide to Credit Union Performance walks through the broader execution-layer architecture.
Beyond Colorado: The Exemption Won’t Be the Last One to Disappear
Colorado has already reversed course once, repealing a broader AI law and replacing it with a narrower one weeks before the original law’s effective date, under industry and federal political pressure that included a Trump administration lawsuit.
State AI legislation overall is not slowing: lawmakers introduced 1,561 AI-related bills across 45 states as of March 2026, already ahead of the 1,208 introduced in all of 2025, of which 145 were enacted (MultiState.ai AI Legislation Tracker, 2026), while federal guidance still excludes generative and agentic AI from scope (OCC, 2026).
Expect more exemptions like Colorado’s old one to disappear, and more shortcuts like this one to replace them, each testing the same question: can the bank name, source, and retain what happened.
A compliance patch built to satisfy ADMTA’s exact language will need to be rebuilt the next time a state changes the rules, which Colorado has already shown can happen with little notice.
A governed execution layer that already sequences, validates, and logs every retrieval and action against core banking systems gives the bank an underlying record it can adapt to the next requirement, rather than rebuilding the compliance mechanism from scratch.
For SI and CCaaS Partners
- The eliminated exemption creates near-term implementation demand for partners already inside a bank’s CCaaS and core banking stack, and the Reg B shortcut gives that work a clear, scoped shape.
- The gap is rarely a missing connector; it is the absence of a governed sequence and audit trail behind the connectors that already exist.
- That is exposure if left unaddressed, and a well-defined engagement (mapping which AI tools materially influence lending decisions versus exempt fraud and identity tools, then building the version-and-data-source audit trail into the client’s stack) for partners positioned to deliver it now.
Conclusion
The exemption Colorado banks used to rely on is gone, and the shortcut that replaced it is real but conditional. An existing Reg B letter can satisfy the new disclosure rule outright, if it can name the AI system, its data source, and an authorized reviewer, and retain that record for three years.
Most institutions already have AI already in production. Few have the governed execution layer that lets an existing compliance document tell that story. Banks that treat this as an architecture question, not a disclosure-language question, will be able to use the shortcut Colorado gave them instead of discovering, one denied loan at a time, that they cannot.