Skip to content

AI Governance & Ethics

Build the AI Inventory Colorado Compliance Requires

Colorado’s AI law turns system purpose and decision influence into compliance facts. A recruiting ranker shows how to document vendors, impact assessments, notices, and appeals.

Irene VaskoGovernance & Ethics Writer

August 9, 2026 · 8 min read

Recruiting workflow inventory showing an AI ranker, assessment status, applicant notice, and appeal owner.
Recruiting workflow inventory showing an AI ranker, assessment status, applicant notice, and appeal owner.

A useful inventory starts with a decision, not a product list. Consider a recruiting system that scores applicants, ranks the shortlist, and sends that ranking to a hiring manager considering a Colorado resident. Internally, give that workflow an identifier such as CO-HR-017. That record will be our anchor.

The vendor may describe its product as matching software, an analytics platform, or an AI copilot. None of those labels resolves the Colorado question. The relevant test in the enacted [Colorado Artificial Intelligence Act](https://leg.colorado.

gov/bills/sb24-205) is whether an artificial intelligence system is “a substantial factor in making a consequential decision.” Employment is one of the covered decision areas.

Colorado delayed the law’s effective date to June 2026 through separate enacted legislation. That gives organizations more preparation time, but it does not turn proposed amendments or possible rulemaking into current requirements. The statute is the baseline; the Colorado Attorney General’s AI materials should be monitored for implementation guidance and rules.

Start with the consequential decision

A consequential decision is one that has a material legal or similarly significant effect on access to, or the cost or terms of, specified services and opportunities. The statute covers areas including employment, housing, lending, insurance, health care, education, essential government services, and legal services.

Ask business owners for workflows in those areas before asking them for AI products. Recruiting should return applicant screening, interview selection, compensation recommendations, and termination support. Lending should return application approval, credit limits, and pricing. A software catalog organized around licenses will miss internally built models, spreadsheet scoring tools, application programming interface calls, and AI features switched on inside products the company already owns.

For CO-HR-017, the inventory boundary begins when applicant data enters the recruiting system and ends when the manager advances or rejects the applicant. Resume parsing is inside the boundary because it supplies structured data to the ranker. The email service that delivers a rejection is connected to the workflow, but it is not itself making or influencing the employment decision.

The distinction matters. Colorado excludes some systems performing narrow procedural tasks or improving the result of a completed human activity, provided they do not replace or influence the decision. A transcription tool that records a completed interview may fit that description. A model that summarizes the interview and recommends “do not advance” requires a closer substantial-factor analysis.

Record influence, not the human-in-the-loop label

A human-in-the-loop system has a person positioned somewhere in the decision process. The phrase does not establish that the person exercises meaningful judgment, and it does not remove a system from scope.

For each workflow, document what the model produces, who receives the output, and how that output changes the decision. Colorado’s definition of substantial factor includes AI output used as a primary basis for a consequential decision and output capable of altering the outcome. It also reaches certain AI-generated predictions, recommendations, or content about a consumer when those outputs are communicated to a human decision-maker and used in the decision.

CO-HR-017 should therefore say more than “manager reviews score.” Record whether applicants below a threshold disappear from the manager’s queue, whether the default sort puts high-scoring applicants first, whether managers can retrieve filtered applicants, and whether overrides are logged. A ranker can shape an outcome without issuing the final rejection, particularly when its interface controls which records a person sees.

Use a short role classification in the inventory:

  1. Determines: the system issues or automatically executes the decision.
  2. Recommends: its score, ranking, prediction, or generated content can alter the outcome.
  3. Supports: it supplies information, while documented controls prevent that output from steering the decision by itself.
  4. Administrative: it acts after the decision or performs a narrow task unrelated to the judgment.

Treat this classification as a documented conclusion, not a permanent property. If CO-HR-017 initially summarizes resumes but later filters applicants below a score, its role has changed even if the vendor and product name remain the same.

Make the vendor supply usable evidence

Colorado assigns developers of high-risk AI systems disclosure duties intended to help deployers complete their own assessments. A developer is generally the organization that develops or intentionally and substantially modifies the system; a deployer uses it to make a consequential decision.

Procurement should request the system’s intended uses, reasonably foreseeable misuses, input and output data categories, known limitations, performance evaluations, and measures used to reduce algorithmic discrimination. Algorithmic discrimination means unlawful differential treatment or impact that disfavors a protected group through an AI system.

Marketing documents are weak evidence. For CO-HR-017, ask the vendor for technical documentation describing how applicant scores are produced, which fields affect them, what population was used for evaluation, how missing data behaves, and whether customers can change thresholds. Obtain version or release identifiers where the vendor supplies them, because an impact assessment tied only to a product name cannot show which system was reviewed.

Also record evidence gaps. A vendor that will not disclose evaluation methods may still be usable, but the deployer must decide whether it can assess foreseeable discrimination without that material. The tradeoff is concrete: independent testing costs staff time and access to representative data, while accepting the gap weakens the organization’s ability to support its assessment and monitor the system.

Contract language should require notice of intentional and substantial modifications, access to documentation needed for assessments, cooperation on consumer corrections and appeals, and retention of relevant outputs. Procurement cannot outsource the deployer’s duties by stating that the vendor is responsible for compliance.

Turn the record into an assessment schedule

Colorado requires deployers to maintain a risk management policy and program for high-risk systems. It also requires an impact assessment at least annually and within 90 days after an intentional and substantial modification becomes available.

The inventory should drive those deadlines. CO-HR-017 needs an owner, last-assessment date, next due window, deployed configuration, covered Colorado population, and modification trigger. Connect those fields to change management so that replacing the ranking model, adding interview-video analysis, or changing an exclusion threshold opens a review rather than waiting for the annual calendar.

The assessment must address the system’s purpose and deployment context, benefits, foreseeable risks of algorithmic discrimination, risk mitigations, data categories, outputs, transparency measures, monitoring, and safeguards. It must also include an analysis of whether deployment poses such discrimination risks. The organization should retain the completed assessment and supporting records according to the statute’s retention requirements.

A generic vendor assessment does not answer how CO-HR-017 behaves inside this employer. The deployer chooses the job families, thresholds, data sources, override permissions, and fallback procedure. Those configuration decisions can create risks absent from the vendor’s reference deployment.

Testing also needs a failure response. If monitoring finds a score distribution that may disadvantage a protected group, the fallback could suspend automated filtering while preserving resume parsing, route every applicant to manual review, and retain the affected outputs for investigation. Manual review increases processing time and can reintroduce inconsistent human judgment, but “keep using the ranker while the team investigates” is not a control.

The NIST AI Risk Management Framework can help structure ownership, measurement, and monitoring. It is voluntary guidance, not a substitute for Colorado’s statutory requirements.

Attach notices and appeals to the workflow

For covered deployments, Colorado requires notice to a consumer before a high-risk AI system makes a consequential decision. The notice must disclose that such a system is being deployed, explain its purpose and the nature of the decision, provide contact information, and direct the consumer to the deployer’s public statement about its high-risk systems.

CO-HR-017 should link to the exact applicant-facing notice and identify where it appears. A privacy policy buried in a footer is difficult to verify as pre-decision notice. The inventory record should capture the delivery event, notice version, language, and channel so the organization can show which applicant received what.

When a consequential decision is adverse, the required disclosure becomes more specific. The deployer must provide the principal reason or reasons, state the degree and manner in which the AI system contributed, identify the types and sources of data used, and explain the consumer’s opportunities to correct inaccurate personal data and appeal the decision. The appeal must allow human review when technically feasible.

That requirement affects system design. If the ranker stores only a final score, the employer may be unable to explain which information drove a rejection. CO-HR-017 should therefore point to retained input references, output logs, model or ruleset identifiers, override records, and the person or team assigned to appeals. Logging carries storage, security, and access-control costs; failing to log can make the required explanation impossible to reconstruct.

Test the appeal path with a deliberately incorrect applicant record. Change a credential, request correction, rerun the relevant step, and confirm that the reviewer can see the original decision without treating the model’s output as presumptively correct. A mailbox that forwards complaints to the same untrained hiring manager is not a meaningful fallback.

Keep one auditable system record

The finished CO-HR-017 record should connect the business decision, technical components, vendor evidence, substantial-factor analysis, assessment history, monitoring results, notices, adverse-decision explanation, correction route, and human-review owner. Links are better than copied documents because they reduce stale duplicates, provided permissions and retention controls preserve the underlying evidence.

Assign one accountable business owner and separate operational contributors. Recruiting may own the decision, engineering may own logs, procurement may own vendor documents, and compliance may maintain the assessment schedule. The inventory fails when each team assumes another one holds the receipt.

Review triggers should include a new decision use, a changed data source, an intentional and substantial model modification, a new Colorado consumer population, or a changed threshold that affects who advances. Product-name changes alone are noise. A material workflow change matters even when the product name stays fixed.

Questions people ask

Does every

AI feature need to enter the Colorado high-risk inventory?

No. Start with AI systems used in covered consequential decisions, then document whether each system determines, recommends, supports, or merely administers the outcome. Keep excluded systems in a screening register with the reason for exclusion, because later configuration changes can turn a procedural feature into a substantial factor.

Is a recruiting score covered if a manager makes the final decision?

It can be. A human’s formal authority does not settle the issue when a score filters the queue, changes ranking, supplies a recommendation, or otherwise can alter the outcome. Record actual interface behavior, override access, and logs rather than relying on a “human-in-the-loop” description.

Can the vendor complete the impact assessment for the employer?

A vendor can supply evaluations and technical documentation, but the deployer must assess its own deployment context under the statute. The employer controls which jobs use CO-HR-017, what applicant data enters it, how managers consume rankings, and what happens when monitoring identifies a problem.

What should the inventory preserve for an applicant appeal?

Preserve the notice version, relevant input sources, system output, model or ruleset identifier, decision reason, AI contribution, corrections, and human-review disposition under an appropriate retention policy. The record must let a reviewer reconstruct the decision without granting unnecessary access to other applicants’ data.

ShareFacebook
ai regulationai governancecolorado ai acthigh-risk aiai inventoryimpact assessmentsalgorithmic discrimination

One story a day

The story of the day, in your inbox

One real story about AI each morning — no hype, no alarm, just company for the road.

Read next

Laptop displaying a cropped airport image beside metadata fields and a Content Credentials verification panel.

AI Governance & Ethics

What an AI-Generated Image Label Can Actually Prove

A visible badge, file metadata, generation log, and signed Content Credential answer different questions. Cropping and reposting expose the gaps between them.

Irene Vasko · 8 min read

A support chat labeled Automated assistant beside a phone displaying an incoming customer-service callback.

AI Governance & Ethics

When a Customer-Service Bot Has to Say It Is a Bot

There is no blanket U.S. disclosure rule. A practical answer depends on where the customer is, what the bot is doing, and whether chat becomes an AI-generated call.

Irene Vasko · 8 min read

A laptop displaying a hiring bias-audit table beside a printed job notice and handwritten calculation notes.

AI Governance & Ethics

How to Read NYC’s Hiring-AI Bias Audit Before You Apply

A public audit can reveal which hiring system was tested, whose outcomes were counted, and where selection rates diverged. It can also conceal job-level differences and omit demographic groups.

Irene Vasko · 8 min read