Close this menu

NetChoice Comments for the Record on Colorado’s Pre-Rulemaking Considerations for the Automated Decision-Making Technology Act and the Chatbot Safety Act

NetChoice submitted comments highlighting our concerns and suggestions for Colorado’s Automated Decision-Making Technology Act and Chatbot Safety Act. We advocate for aligning regulatory definitions with existing legal frameworks to prevent overbroad restrictions on technology and innovation. Additionally, we outline key recommendations for both pieces of legislation, pushing for flexible compliance standards, objective chatbot safety criteria, and practical age-estimation methods to safeguard consumer privacy and free expression.

NetChoice Comments for the Record on Pre-Rulemaking Considerations for the Automated Decision-Making Technology Act (Senate Bill 26-189) and the Chatbot Safety Act (House Bill 26-1263)

July 13, 2026

The Honorable Phil Weiser
Attorney General of Colorado
Colorado Department of Law
Ralph L. Carr Colorado Judicial Center
1300 Broadway
Denver, CO 80203

NetChoice is a national trade association of leading internet and technology businesses that promotes free expression and free enterprise online. Our members build, deploy, and integrate the technologies these Acts address: they will be “developers” and “deployers” under the ADMT Act and “operators” under the Chatbot Safety Act. We appreciate the Department’s decision to seek informal input before drafting regulations, and we submit this comment to identify the issues we believe are most consequential for the rulemaking. Given the scope of both Acts, we offer principles-level recommendations here and intend to provide detailed, sector-specific comments during the formal notice-and-comment phase. 

We are encouraged by the Department’s five guiding principles, particularly its commitments to harmonize with existing frameworks, facilitate efficient compliance, and allow for innovation. Each recommendation below is offered in service of those principles. 

I. Overarching Recommendations

Anchor definitions to existing law. The most valuable thing this rulemaking can do is situate both Acts within frameworks that businesses and consumers already understand. The Colorado Privacy Act’s controller/processor architecture maps closely onto the ADMT Act’s developer/deployer distinction, and federal adverse-action regimes—including the Fair Credit Reporting Act (FCRA) and the Equal Credit Opportunity Act (ECOA)—already govern much of the disclosure territory the ADMT Act covers. The FCRA and ECOA are agnostic to whether or not artificial intelligence or any other technology played a role. Rules that align with these frameworks will accelerate compliance; rules that diverge from them will produce duplicative notices that confuse the consumers they are meant to inform. 

Prevent overbroad scope through examples and carve-outs. The single greatest risk of unintended consequences under either Act is definitional overbreadth. Read literally, technology that “processes personal data and uses computation to generate output” could describe calendaring software, search functions, tutoring services, and even fitness wearables. The Department should use its expressly granted authority to clarify “materially influence” and to delineate ADMTs from technologies that merely “summarize, organize, translate, draft, route, or present information,” with concrete illustrative examples of covered and non-covered uses. This delineation should be narrow in order to avoid restricting innovation, given that Colorado consumers are adequately protected by existing state and federal laws. 

Prefer safe harbors and deemed-compliance pathways to prescriptive mandates. Where an entity already complies with a federal or state regime governing the same conduct—adverse-action notices in lending, for example—the rules should exempt that entity from additional regulation. This approach honors the General Assembly’s stated intent that disclosure requirements account for sector-specific practices, and it avoids forcing regulated entities to choose between conflicting obligations.

II. The ADMT Act

“Materially influence” should require substantial, actual reliance. The statute’s “non-de minimis factor” language should be clarified so that an ADMT output materially influences a decision only when a decision-maker substantially relies on it in producing the outcome—not whenever an automated output is merely present somewhere in a workflow. Objective indicators could include whether the output was designed and documented for the specific decision at issue and whether the outcome would plausibly have differed without it. Illustrative examples distinguishing material influence from incidental or background use, including sector-specific examples, would meaningfully reduce uncertainty. 

Developer and deployer roles should turn on intent and configuration. A developer of general-purpose technology should not become a covered “developer” because a downstream customer independently configures that technology to influence consequential decisions. The rules should look to how a system is designed, marketed, documented, and contracted—factors the Act itself identifies—so that obligations attach to the entity actually positioned to fulfill them. 

Disclosure standards should explain decisions, not expose systems. Post-adverse-outcome disclosures should be judged by whether they give the consumer a plain-language understanding of the decision and the ADMT’s role in it. The rules should confirm that the right to “additional information” does not require disclosure of trade secrets, model weights, or proprietary system details, and should permit existing federally mandated adverse-action notices to satisfy overlapping requirements. Disclosures should also be limited to factual and uncontroversial content. Requiring otherwise would trigger heightened First Amendment scrutiny. 

To be “commercially reasonable,” meaningful human review must remain flexible. The Department should confirm that decision volume, organizational size and capacity, cost, the availability of qualified reviewers, and the nature of the decision are all relevant to what “meaningful human review” is commercially reasonable, and should decline to impose uniform mandatory timelines across all sectors and decision types. The rules should also recognize that meaningful review evaluates the decision and its primary evidence; it does not require a human to re-derive or audit the technical output of the system. Over-mandated human involvement risks reintroducing the inconsistency that well-designed automated tools reduce.

One notice should suffice. The Department should confirm that pre-use notice may be integrated into an entity’s existing privacy notice or posted disclosures under the Colorado Privacy Act, so long as it is reasonably proximate to the relevant interaction. Layered, duplicative notices do not inform consumers; they train consumers to ignore notices altogether.

III. The Chatbot Safety Act

Scope should track the risk the Act targets. The Act’s core concern is companion-style conversational services marketed to consumers. The rules should clarify that a service which “primarily simulates human conversation” excludes general-purpose productivity and enterprise tools, customer-service functions, and coding or technical assistants. The rules should also clarify that “publicly available” excludes enterprise, educational, and other authenticated business-to-business deployments. 

Age estimation must be construed to avoid constitutional and privacy hazards. Courts have repeatedly enjoined state statutes imposing age-verification mandates on online services—including in NetChoice challenges brought in Arkansas, Mississippi, and Louisiana—because such mandates burden adults’ and minors’ access to lawful speech. The Department should explicitly recognize “commercially reasonable methods or generally accepted methods to estimate” age as what it says: estimation, satisfied by signals-based approaches and self-declaration absent willfully disregarded contrary information—not document upload, biometric scanning, or identity verification. A safe harbor along these lines would also serve the Act’s own privacy aims: aggressive age assurance requires operators to collect more sensitive data about minors, not less. The rules should likewise give concrete examples of what does and does not constitute “clear and convincing information” of minority status. 

“Emotional dependence” needs objective, conduct-based indicators. The Department has asked how to distinguish roleplay, companionship, and emotional support from prohibited simulation of emotional dependence or isolation. Regulating “response[s]” that “simulate[] emotional dependence” is a blatantly content-based standard, thereby courting strict scrutiny. Thus, that standard needs to be defined to sweep in as little speech as possible. We urge conduct-based lines: outputs that discourage a minor’s real-world relationships, claim exclusivity, or penalize disengagement are categorically different from ordinary personalization, memory, and responsiveness—qualities that make services useful and that consumers expect. “Rewards” designed to increase engagement should be defined so as not to capture baseline product quality. And “technically feasible” and “reasonable” measures should be assessed against documented, state-of-the-art safety practices—demonstrated through an operator’s testing and internal documentation—rather than prescriptive technology mandates that will be outdated before the rules take effect. 

Crisis-protocol reporting should measure potentially harmful user prompts while protecting user privacy. Raw referral counts are unreliable indicators of efficacy and create perverse incentives—rewarding over-referral or threshold-tuning rather than genuinely effective intervention. Metrics should be normalized and contextualized, standardized where possible, and scaled to operator size and service type. Because the Act requires public posting of report data, the rules must draw a clear line between publishable aggregates and confidential material: safeguard methodologies, red-team results, and detection techniques must remain confidential, both to protect trade secrets and because publishing them provides a roadmap for circumvention that endangers the very users the Act protects. 

Thank you for the opportunity to provide input. We welcome any questions and would be glad to serve as a resource to the Department throughout this rulemaking. 

Sincerely, 

Patrick Hedger 
Director of Policy, NetChoice (The views of NetChoice expressed here do not necessarily represent the views of all NetChoice members.)

NetChoice is a trade association that works to protect free expression and promote free enterprise online.