Featured image titled Colorado ADMTA for Banks: Can You Explain an AI Decision?
October 9, 2026

Colorado ADMTA: The Notice May Be Covered. The Decision Record Still Has to Exist.

Table of Contents

Regulatory status as of October 9, 2026: proposed rules pending, interim draft released October 6, 2026.

Key Takeaways graphic summarizing Colorado ADMTA requirements for banks, consumer information rights after adverse outcomes, and operational recordkeeping challenges for AI decisions.

What Colorado’s ADMTA Actually Requires From Banks and Credit Unions

The Reg B Shortcut Has Conditions

Colorado’s Automated Decision-Making Technology Act (ADMTA), SB 26-189, takes effect January 1, 2027, and applies to consequential decisions made on or after that date.

In lending, a consequential decision includes a decision that relates to the provision of, or a consumer’s access to or eligibility for, a financial or lending service, as well as certain decisions about a differentiated price or other material terms.

For consequential decisions involving the offering, denial, pricing, servicing, or other material terms of credit, a creditor can satisfy the Act’s notice or disclosure requirements that relate to the same decision or adverse outcome through an ECOA/Regulation B notice, and where applicable an FCRA notice, provided the federal notice also satisfies the applicable Colorado requirements.

That can eliminate a separate or duplicative Colorado notice, but it does not eliminate the underlying disclosure and recordkeeping work.

The institution still has to describe the role the covered ADMT played, respond to requests for information about it, offer meaningful human review on request where commercially reasonable, and retain compliance records for at least three years.

When an AI-influenced decision spans several systems, that information may have to be assembled afterward from records each system created independently.

What Consumers Can Request After an Adverse Outcome

Diagram outlining the four key elements of an ADMTA decision record.

ADMTA’s disclosures work in three stages: a notice before the covered ADMT is used, a disclosure within 30 days after a consequential decision that results in an adverse outcome, and information the consumer can then request.

To satisfy the 30-day disclosure through the federal shortcut, a creditor’s adverse action notice would carry:

1. Federal lending disclosures (Regulation B/ECOA) such as action taken, principal reasons, and the anti-discrimination notice.

2. Credit report disclosures (FCRA), where applicable, such as credit score used, free report rights, and dispute instructions.

3. A plain-language description of the decision and the role the covered ADMT played in it.

4. Instructions and a simple process for requesting additional information about the covered ADMT and its inputs, plus an explanation of the consumer’s rights and how to exercise them.

The information a consumer can then request includes the covered ADMT’s name, version number if applicable, developer, and the types, categories, and sources of personal data used, to the extent the deployer received the necessary information from the developer.

Consumers can request access to personal data used in the consequential decision, correction of factually incorrect or materially inaccurate personal data, and meaningful human review and reconsideration, to the extent commercially reasonable.

The statute defines meaningful human review as review by a designated individual with authority to approve, modify, or override the consequential decision, who is trained to conduct the review, considers the evidence, and does not default to the system’s output. The reviewer must also have enough information about the covered ADMT’s intended use, limitations, and input categories to conduct that review.

Both developers and deployers must retain records reasonably necessary to demonstrate compliance for at least three years.

The statute’s examples of deployer records include, as applicable, covered ADMT version identifiers, changelogs, and documentation of material mitigation changes. It does not prescribe a technical schema for those records.

What Falls Outside ADMTA’s Scope

Not every contact center AI interaction is a covered ADMT use.

ADMTA excludes several categories of technology and activity. These include tools used solely to summarize, organize, route, or present information for human review, as well as certain routine or low-stakes processes.

Customer-facing conversational technology can also fall outside the ADMT definition when it is not intended, marketed, configured, advertised, or contracted for use in a consequential decision and is subject to an acceptable-use policy prohibiting such use.

The Act also excludes certain cybersecurity, anti-money-laundering, sanctions-compliance, fraud-prevention, and identity-verification activities, among other specified uses.

Infographic detailing the Colorado ADMTA rulemaking watch timeline and key dates.

Why an AI-Influenced Decision Spans Systems Without a Shared Record

AI Adoption Is Running Ahead of Governance

Banking AI adoption is moving quickly. Cornerstone Advisors’ 2026 research,  reports that 49% of banks and 59% of credit unions have deployed generative AI.

Separately, Deloitte’s 2026 Banking on Trust research, a survey of global banks, found that 63% of surveyed bank employees use AI weekly, up from 30% in 2025.

The challenge is not simply adoption. Deloitte’s 2026 banking outlook identifies data foundations as one factor slowing AI readiness, while its review of the top 40 U.S. banks found predominantly reactive, siloed AI efforts that can produce inconsistent value.

Only 13% of global banks in Deloitte’s Banking on Trust research have reached the highest AI governance maturity stage.

Diagram illustrating how AI decisions span multiple independent systems without a shared sequential record.

That gap shows up in the decision record in three ways. First, a loan eligibility check may draw on the core system for account history, a scoring tool for risk, and sometimes a third-party data feed, and each system logs its own activity in its own format.

Second, no shared record captures the sequence across all three, so the institution may not be able to show which one ran first, or whether the score used data that was current at the time.

Third, because AI projects are often deployed one use case at a time, the logging built for one model may not match the logging built for another, even inside the same institution.

The data to answer “What happened?” often exists somewhere. It may not exist as one attributable record.

Infographic summarizing AI adoption trends and governance challenges in banking for Colorado ADMTA compliance.

Logs Are Not Records: Storage Versus Sequencing

Storage answers one question: “Do we have data about this decision?” Sequencing answers another: “Can we reconstruct what happened, in what order, and which systems and people were involved?”
Those are different capabilities.

ADMTA requires deployers to retain records reasonably necessary to demonstrate compliance for at least three years. The statute does not prescribe a universal technical schema for those records.

The operational question for an institution is whether its existing systems can produce a defensible, decision-specific record when the information is needed.

Separately, the Federal Reserve, FDIC, and OCC issued revised interagency model risk management guidance (SR 26-2) on April 17, 2026. The guidance addresses model development and use, validation and monitoring, and governance and controls, and takes a risk-based approach tailored to an institution’s model risk profile, size, and complexity.

It expressly places generative and agentic AI models outside its scope, and the agencies state that it does not establish enforceable or prescriptive requirements.

Documentation is a long-standing part of bank governance. The harder part is producing it for a specific AI-influenced decision, in sequence.

A record that can answer a consumer’s request should be able to show that a specific retrieval happened before a specific validation, which happened before a specific action, all tied to one interaction.

What a Governed Decision Record Captures on Every Step

Diagram showing a five-step ADMTA-compliant decision record model for AI interactions.

ADMTA does not prescribe a technical schema. But an institution evaluating whether it can explain an AI-influenced decision should be able to reconstruct at least five stages of the interaction

    • Database icon with an upward-pointing arrow. Retrieve: What system supplied the information used in the decision?
    • Document icon with horizontal text lines and a checkmark badge. Validate: What information or condition was checked before the action?
    • Icon showing a user silhouette surrounded by circular arrows with checkmark and cross symbols. Decide: Which covered ADMT materially influenced the consequential decision, and which version was involved?
    • Gear icon with a checkmark inside. Execute: What action followed from the decision, and which system executed it?
    • Star icon inside a circle. Review: If the consumer requests reconsideration, which designated reviewer handles it, and what information is available to them?

Identity verification usually happens early in the interaction. It is generally outside ADMTA’s scope, but recording when it occurred still helps establish the sequence.
This is an operational model for evaluating whether an institution can reconstruct an AI-influenced decision, not a statutory field list.

This is where the execution layer matters. Connectivity moves data. CCIP controls execution.

Rather than treating each system interaction as a separate integration, an execution layer governs what happens between the AI interaction, the systems of record, and the action that follows, applying the organization’s rules and controls as the interaction moves from request to execution.

The pattern matters more than any single vendor’s implementation of it. An institution evaluating its own architecture against this sequence, rather than against a product feature list, will see its gaps more clearly.

How the Roles Map

1. Retrieve: CCIP role: Govern retrievals made through CCIP during the interaction.

2. Validate: CCIP role: Apply configured validation and execution controls to information retrieved through CCIP during the interaction.

3. Decide: AI system role: The AI agent or other covered ADMT that makes or materially influences the decision.

4. Execute: CCIP role: Govern and execute authorized actions through CCIP during the interaction.

5. Review: Institution role: Provide meaningful human review as the Act provides. CCIP’s pre-execution approvals are separate from ADMTA’s right to meaningful human review.

Infographic detailing key architectural takeaways for ADMTA compliance across five decision stages.

What ADMTA Means for CCaaS Partners and System Integrators

For System Integrators

For SIs, the issue is not simply whether a bank has an AI model in production. It is whether the implementation can preserve the information needed to explain how that model was used.

SB 26-189 places specific documentation responsibilities on developers of covered ADMT, including information about intended and inappropriate uses, categories of training data, known limitations, appropriate use and monitoring, and meaningful human review.

Developers must also provide notice of material updates and retain records reasonably necessary to demonstrate compliance for at least three years.

The statute also defines developers broadly enough to include parties that intentionally and substantially modify an ADMT so that it becomes a covered ADMT.

For an SI, that makes implementation boundaries, documentation handoffs, and responsibility for material modifications important parts of the architecture conversation.

Infographic detailing key ADMTA considerations and compliance implications for CCaaS partners.

The Question to Answer Before January 2027

Colorado’s ADMTA creates a disclosure and recordkeeping obligation around consequential decisions influenced by covered ADMT. The statute does not prescribe a universal technical architecture for producing that record.

But the operational test is straightforward: when an adverse outcome occurs, can the organization explain what decision was made, what role the ADMT played, what information was involved, and how the consumer can exercise their rights?

For banks, credit unions, and their technology partners, that makes the decision record an architecture question as much as a compliance question.

Organizations that can trace an AI-influenced interaction from retrieval to decision to execution can use that record when a consumer requests information or review, or when the institution needs to demonstrate compliance.

See how CCIP governs AI agent execution across Jack Henry, Fiserv, and FIS.
Explore CCIP

Frequently Asked Questions

Colorado's Automated Decision-Making Technology Act, SB 26-189, takes effect January 1, 2027, and applies to consequential decisions made on or after that date. The Attorney General is required to adopt rules by that date to clarify and implement specified provisions, including post-adverse-outcome disclosure requirements. Proposed rules were filed August 11, 2026, an interim draft was released October 6, 2026, and the rules remain in formal rulemaking.
It can, for consequential decisions involving credit, satisfy the related notice or disclosure requirements for the same decision or adverse outcome, if the creditor's ECOA/Regulation B notice, and FCRA notice where applicable, also satisfies the applicable Colorado requirements. In that circumstance, the creditor does not have to provide a separate or duplicative Colorado notice.
No. Coverage depends on the statutory definition of ADMT, whether the technology materially influences a consequential decision, and the covered domain involved. The statute also excludes certain conversational technologies that are not intended for consequential decisions and are subject to appropriate use restrictions, along with certain routine, administrative, fraud-prevention, and identity-verification activities.

Overview

  • We enable brands to create superior agent and customer experience by offering next-gen contact center integrations with 100+ third-party applications.
  • 100+ third-party app integrations
  • 17+ Years of Experience
  • 350+ Deployments in 20+ Countries

In a hurry?

Connect with us right away through instant chat.

Download Brochure

We’ll send the brochure to the details below
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
Your data is securely managed. To know more, visit our Privacy Policy

Fill up the form to watch the video

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form

Fill up the form to watch the video

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Request a Demo

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form

Download Use Case

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Build, Grow, and Scale Your Way

Referral Program

Bring us more sales opportunities through referrals and get rewarded for every referral that becomes our customer.

Reseller Program

Get certified to include NovelVox products in your offerings and get a commission each deal when you resell.

Implementation Program

Develop your own integrations with NovelVox and get access to all our pre-built tools and proprietary solutions.

In a hurry?

Connect with us right away through instant chat.

Request to Become a Partner

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
Your data is securely managed. To know more, visit our Privacy Policy

Watch Video

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form

Watch Video

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form

Subscribe to our free newsletter and get blog updates in your inbox

Request to Become a Partner

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form

Download Guide

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Refer an Opportunity

  • This field is for validation purposes and should be left unchanged.
  • About Yourself

Overview

  • We enable brands to create superior agent and customer experience by offering next-gen contact center integrations with 100+ third-party applications.
  • 100+ third-party app integrations
  • 17+ Years of Experience
  • 350+ Deployments in 20+ Countries

In a hurry?

Connect with us right away through instant chat.

Explore NovelVox Solutions

We will reach on the below details
  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
Your data is securely managed. To know more, visit our Privacy Policy