Regulatory status as of October 9, 2026: proposed rules pending, interim draft released October 6, 2026.
What Colorado’s ADMTA Actually Requires From Banks and Credit Unions
The Reg B Shortcut Has Conditions
Colorado’s Automated Decision-Making Technology Act (ADMTA), SB 26-189, takes effect January 1, 2027, and applies to consequential decisions made on or after that date.
In lending, a consequential decision includes a decision that relates to the provision of, or a consumer’s access to or eligibility for, a financial or lending service, as well as certain decisions about a differentiated price or other material terms.
For consequential decisions involving the offering, denial, pricing, servicing, or other material terms of credit, a creditor can satisfy the Act’s notice or disclosure requirements that relate to the same decision or adverse outcome through an ECOA/Regulation B notice, and where applicable an FCRA notice, provided the federal notice also satisfies the applicable Colorado requirements.
That can eliminate a separate or duplicative Colorado notice, but it does not eliminate the underlying disclosure and recordkeeping work.
The institution still has to describe the role the covered ADMT played, respond to requests for information about it, offer meaningful human review on request where commercially reasonable, and retain compliance records for at least three years.
When an AI-influenced decision spans several systems, that information may have to be assembled afterward from records each system created independently.
What Consumers Can Request After an Adverse Outcome
ADMTA’s disclosures work in three stages: a notice before the covered ADMT is used, a disclosure within 30 days after a consequential decision that results in an adverse outcome, and information the consumer can then request.
To satisfy the 30-day disclosure through the federal shortcut, a creditor’s adverse action notice would carry:
1. Federal lending disclosures (Regulation B/ECOA) such as action taken, principal reasons, and the anti-discrimination notice.
2. Credit report disclosures (FCRA), where applicable, such as credit score used, free report rights, and dispute instructions.
3. A plain-language description of the decision and the role the covered ADMT played in it.
4. Instructions and a simple process for requesting additional information about the covered ADMT and its inputs, plus an explanation of the consumer’s rights and how to exercise them.
The information a consumer can then request includes the covered ADMT’s name, version number if applicable, developer, and the types, categories, and sources of personal data used, to the extent the deployer received the necessary information from the developer.
Consumers can request access to personal data used in the consequential decision, correction of factually incorrect or materially inaccurate personal data, and meaningful human review and reconsideration, to the extent commercially reasonable.
The statute defines meaningful human review as review by a designated individual with authority to approve, modify, or override the consequential decision, who is trained to conduct the review, considers the evidence, and does not default to the system’s output. The reviewer must also have enough information about the covered ADMT’s intended use, limitations, and input categories to conduct that review.
Both developers and deployers must retain records reasonably necessary to demonstrate compliance for at least three years.
The statute’s examples of deployer records include, as applicable, covered ADMT version identifiers, changelogs, and documentation of material mitigation changes. It does not prescribe a technical schema for those records.
What Falls Outside ADMTA’s Scope
Not every contact center AI interaction is a covered ADMT use.
ADMTA excludes several categories of technology and activity. These include tools used solely to summarize, organize, route, or present information for human review, as well as certain routine or low-stakes processes.
Customer-facing conversational technology can also fall outside the ADMT definition when it is not intended, marketed, configured, advertised, or contracted for use in a consequential decision and is subject to an acceptable-use policy prohibiting such use.
The Act also excludes certain cybersecurity, anti-money-laundering, sanctions-compliance, fraud-prevention, and identity-verification activities, among other specified uses.
Why an AI-Influenced Decision Spans Systems Without a Shared Record
AI Adoption Is Running Ahead of Governance
Banking AI adoption is moving quickly. Cornerstone Advisors’ 2026 research, reports that 49% of banks and 59% of credit unions have deployed generative AI.
Separately, Deloitte’s 2026 Banking on Trust research, a survey of global banks, found that 63% of surveyed bank employees use AI weekly, up from 30% in 2025.
The challenge is not simply adoption. Deloitte’s 2026 banking outlook identifies data foundations as one factor slowing AI readiness, while its review of the top 40 U.S. banks found predominantly reactive, siloed AI efforts that can produce inconsistent value.
Only 13% of global banks in Deloitte’s Banking on Trust research have reached the highest AI governance maturity stage.
That gap shows up in the decision record in three ways. First, a loan eligibility check may draw on the core system for account history, a scoring tool for risk, and sometimes a third-party data feed, and each system logs its own activity in its own format.
Second, no shared record captures the sequence across all three, so the institution may not be able to show which one ran first, or whether the score used data that was current at the time.
Third, because AI projects are often deployed one use case at a time, the logging built for one model may not match the logging built for another, even inside the same institution.
The data to answer “What happened?” often exists somewhere. It may not exist as one attributable record.
Logs Are Not Records: Storage Versus Sequencing
Storage answers one question: “Do we have data about this decision?” Sequencing answers another: “Can we reconstruct what happened, in what order, and which systems and people were involved?”
Those are different capabilities.
ADMTA requires deployers to retain records reasonably necessary to demonstrate compliance for at least three years. The statute does not prescribe a universal technical schema for those records.
The operational question for an institution is whether its existing systems can produce a defensible, decision-specific record when the information is needed.
Separately, the Federal Reserve, FDIC, and OCC issued revised interagency model risk management guidance (SR 26-2) on April 17, 2026. The guidance addresses model development and use, validation and monitoring, and governance and controls, and takes a risk-based approach tailored to an institution’s model risk profile, size, and complexity.
It expressly places generative and agentic AI models outside its scope, and the agencies state that it does not establish enforceable or prescriptive requirements.
Documentation is a long-standing part of bank governance. The harder part is producing it for a specific AI-influenced decision, in sequence.
A record that can answer a consumer’s request should be able to show that a specific retrieval happened before a specific validation, which happened before a specific action, all tied to one interaction.
What a Governed Decision Record Captures on Every Step
ADMTA does not prescribe a technical schema. But an institution evaluating whether it can explain an AI-influenced decision should be able to reconstruct at least five stages of the interaction
-
Retrieve: What system supplied the information used in the decision?
Validate: What information or condition was checked before the action?
Decide: Which covered ADMT materially influenced the consequential decision, and which version was involved?
Execute: What action followed from the decision, and which system executed it?
Review: If the consumer requests reconsideration, which designated reviewer handles it, and what information is available to them?
Identity verification usually happens early in the interaction. It is generally outside ADMTA’s scope, but recording when it occurred still helps establish the sequence.
This is an operational model for evaluating whether an institution can reconstruct an AI-influenced decision, not a statutory field list.
This is where the execution layer matters. Connectivity moves data. CCIP controls execution.
Rather than treating each system interaction as a separate integration, an execution layer governs what happens between the AI interaction, the systems of record, and the action that follows, applying the organization’s rules and controls as the interaction moves from request to execution.
The pattern matters more than any single vendor’s implementation of it. An institution evaluating its own architecture against this sequence, rather than against a product feature list, will see its gaps more clearly.
How the Roles Map
1. Retrieve: CCIP role: Govern retrievals made through CCIP during the interaction.
2. Validate: CCIP role: Apply configured validation and execution controls to information retrieved through CCIP during the interaction.
3. Decide: AI system role: The AI agent or other covered ADMT that makes or materially influences the decision.
4. Execute: CCIP role: Govern and execute authorized actions through CCIP during the interaction.
5. Review: Institution role: Provide meaningful human review as the Act provides. CCIP’s pre-execution approvals are separate from ADMTA’s right to meaningful human review.
What ADMTA Means for CCaaS Partners and System Integrators
For System Integrators
For SIs, the issue is not simply whether a bank has an AI model in production. It is whether the implementation can preserve the information needed to explain how that model was used.
SB 26-189 places specific documentation responsibilities on developers of covered ADMT, including information about intended and inappropriate uses, categories of training data, known limitations, appropriate use and monitoring, and meaningful human review.
Developers must also provide notice of material updates and retain records reasonably necessary to demonstrate compliance for at least three years.
The statute also defines developers broadly enough to include parties that intentionally and substantially modify an ADMT so that it becomes a covered ADMT.
For an SI, that makes implementation boundaries, documentation handoffs, and responsibility for material modifications important parts of the architecture conversation.
The Question to Answer Before January 2027
Colorado’s ADMTA creates a disclosure and recordkeeping obligation around consequential decisions influenced by covered ADMT. The statute does not prescribe a universal technical architecture for producing that record.
But the operational test is straightforward: when an adverse outcome occurs, can the organization explain what decision was made, what role the ADMT played, what information was involved, and how the consumer can exercise their rights?
For banks, credit unions, and their technology partners, that makes the decision record an architecture question as much as a compliance question.
Organizations that can trace an AI-influenced interaction from retrieval to decision to execution can use that record when a consumer requests information or review, or when the institution needs to demonstrate compliance.
See how CCIP governs AI agent execution across Jack Henry, Fiserv, and FIS.
Explore CCIP