Skip to main content

By State / Colorado

Colorado AI Vendor Governance

AI vendors evaluated against Colorado's amended AI law — original SB 24-205 was repealed and replaced by SB 26-189 (signed May 2026, effective January 1, 2027), which narrows the law to a transparency / disclosure regime for automated decision systems and drops the prior risk-management programs, impact assessments, and duty of care.

Colorado — vendors with explicit state engagement, ranked by 4 state-relevant governance axes.

Edition: 2026-Q2State: COVendors: 30State-relevant axes: 4
By Stefan Efros, CEO & Founder, EFROS
Updated ·

Why this state view

Colorado's original SB 24-205 was repealed and replaced by SB 26-189 (signed May 2026, effective January 2027), which narrows the law to a transparency / disclosure regime for automated decision systems and drops the prior risk-management programs, impact assessments, and duty of care. Vendors serving Colorado customers should map their automated-decision disclosure posture to the amended law; NIST AI RMF and ISO/IEC 42001 remain the load-bearing anchors for vendor-side governance evidence.

Primary frameworks anchored

  • NIST AI RMF 1.0 (de-facto procurement anchor)
  • ISO/IEC 42001 (certifiable AI management system)
  • Colorado SB 26-189 (amended AI law — repealed and replaced SB 24-205; transparency/disclosure, effective Jan 1, 2027)
  • Colorado Consumer Protection Act

State-relevant scoring axes

Columns marked with an accent dot in the scorecard below are the axes most relevant to Colorado's regulatory frame. The state-relevance ranking in this view averages vendor performance across these axes only.

  • Colorado AI Act readiness
  • NIST AI RMF self-attestation
  • BAA / DPA available
  • Subprocessor list public
Colorado vendor scoring — state relevance descending. Columns relevant to Colorado regulatory frame are marked with an accent dot.
#VendorCO Rel.ScoreGradeBAAOpt-outUS ResSOC 2ISO 42001NIST AICO AI§1557SR 11-7ABA 512SubprocTC
1Abridge75(4/4)87AYesYesYesYesPartialPartialPartialYesN/AN/AYes5/5
2Thomson Reuters CoCounsel75(4/4)80BYesYesYesYesNoPartialPartialN/AN/AYesYes4/5
3FICO Falcon Fraud Manager + FICO Score AI75(4/4)80BYesYesYesYesNoPartialPartialN/AYesN/AYes4/5
4Microsoft 365 Copilot75(4/4)75BYesYesYesYesPartialPartialPartialPartialPartialPartialYes5/5
5Suki AI75(4/4)72BYesYesYesYesNoPartialPartialPartialN/AN/AYes4/5
6Lexis+ AI63(4/4)76BYesYesYesYesNoPartialNoN/AN/AYesYes4/5
7Westlaw Precision AI63(4/4)76BYesYesYesYesNoPartialNoN/AN/AYesYes4/5
8Harvey63(4/4)74BYesYesYesYesNoPartialPartialN/AN/AYesPartial3/5
9Zest AI63(4/4)74BYesYesYesYesNoPartialPartialN/AYesN/APartial3/5
10Upstart63(4/4)74BYesYesYesYesNoPartialPartialN/AYesN/APartial3/5
11Nuance DAX Copilot (Microsoft)63(4/4)70BYesYesYesYesNoPartialNoPartialN/AN/AYes5/5
12Salesforce Einstein / Agentforce63(4/4)69CYesYesYesYesNoPartialNoPartialPartialN/AYes5/5
13Glean63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
14Arctic Wolf63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
15Huntress63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
16eSentire63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
17Sophos63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
18Unit2163(4/4)68CYesYesYesYesNoPartialNoN/APartialN/AYes4/5
19Ironclad AI50(4/4)63CYesYesYesYesNoNoNoN/AN/APartialYes4/5
20Anthropic Claude50(4/4)58CPartialYesPartialYesNoPartialNoN/AN/AN/AYes4/5
21Google Gemini for Workspace50(4/4)58CPartialPartialYesYesNoPartialNoN/AN/AN/AYes4/5
22OpenAI ChatGPT & API50(4/4)53DPartialPartialPartialYesNoPartialNoN/AN/AN/AYes4/5
23Hummingbird38(4/4)56CYesYesYesYesNoNoNoN/APartialN/APartial3/5
24ConnectWise38(4/4)50DPartialYesPartialYesNoNoNoN/AN/AN/AYes3/5
25Spellbook38(4/4)45DYesYesPartialPartialNoNoNoN/AN/APartialPartial2/5
26Heidi Health38(4/4)45DYesYesPartialPartialNoNoNoPartialN/AN/APartial2/5
27Notion AI25(4/4)33FNoPartialNoYesNoNoNoN/AN/AN/AYes3/5
28Otter.ai13(4/4)25FNoPartialNoYesNoNoNoN/AN/AN/APartial2/5
29Perplexity AI13(4/4)19FNoPartialNoPartialNoNoNoN/AN/AN/APartial2/5
30Meta Llama0(4/4)25FNoYesYesNoNoNoNoN/AN/AN/ANo2/5

How vendors score on Colorado's relevant axes

Yes / partial counts across the full 30-vendor pool, restricted to axes relevant to Colorado's regulatory frame. N/A axes are excluded from the applicable denominator.

CO AI

Colorado AI Act readiness

CO
Yes0/30 (0%)
Partial8/30 (27%)

NIST AI

NIST AI RMF self-attestation

CO
Yes0/30 (0%)
Partial21/30 (70%)

BAA

BAA / DPA available

CO
Yes22/30 (73%)
Partial4/30 (13%)

Subproc

Subprocessor list public

CO
Yes21/30 (70%)
Partial8/30 (27%)

Top 3 vendors on the Colorado-relevant axis subset

Buyer's guide for Colorado

For Colorado-deploying organizations, the highest-leverage axes are NIST AI RMF anchoring (the de-facto procurement standard), explicit engagement with Colorado's amended AI law (SB 26-189 — automated-decision disclosure, effective 2027), and BAA/DPA scope. Vendors that score 'No' on Colorado AI law readiness require deployer-side documentation work.

Operationalize the scoring

Colorado AI Act for Healthcare Deployers

The Index tells you which vendors clear the bar for Colorado engagement. The companion resource tells you how to turn that selection into a deployable governance program with documented evidence.

Colorado AI Act for Healthcare Deployers →

Compare Colorado with other state and sector views

Other state views

Sector views

Scoring as of 2026-05-13from public information (vendor trust portals, BAAs, SOC report cover pages, model cards, vendor documentation). Posture changes frequently — re-verify with the vendor's trust center before contract. State filter views surface vendors with explicit state engagement on the axes most relevant to that state's regulatory frame; they do not replace deployer-side state compliance work. Methodology: read the full methodology.

Turn the scoring into a deployable program

The Index tells you the posture. These engagements turn the posture into operational evidence for Colorado deployments.