Welcome to the forefront of conversational AI as we explore the fascinating world of AI chatbots in our dedicated blog series. Discover the latest advancements, applications, and strategies that propel the evolution of chatbot technology. From enhancing customer interactions to streamlining business processes, these articles delve into the innovative ways artificial intelligence is shaping the landscape of automated conversational agents. Whether you’re a business owner, developer, or simply intrigued by the future of interactive technology, join us on this journey to unravel the transformative power and endless possibilities of AI chatbots.
Monitoring the financial services industry to help companies navigate through regulatory compliance, enforcement, and litigation issues
On August 11, the Colorado Department of Law (DOL) filed proposed rules implementing two significant Colorado artificial intelligence laws, the Automated Decision-Making Technology in Consequential Decisions Act (ADMT Act) and the Conversational Artificial Intelligence Services Act (Chatbot Safety Act), both of which take effect January 1, 2027. As we reported in May (here), the Colorado legislature significantly rewrote its earlier 2024 AI law, replacing the prior framework with a more targeted set of obligations focused on automated decision-making technology (ADMT) in consequential decisions. The proposed rules represent the Attorney General’s effort to flesh out that framework before the upcoming effective date. They also begin to answer several of the questions we flagged as unresolved when the new law was signed. A formal rulemaking hearing has been scheduled on October 26, 2026. Public comments about any proposed revisions to the rules to be presented during the hearing must be submitted by October 5, but all public comments submitted through October 26 will be considered for the final set of rules.
The ADMT Act (Senate Bill 26-189, signed May 2026) creates obligations for both developers and deployers of ADMT used to materially influence “consequential decisions” — defined to include decisions affecting employment, education, financial services, housing, insurance, and other significant areas of consumer life. As discussed in our prior post, the law imposes disclosure, consumer rights, and human review obligations on deployers, and documentation and notification obligations on developers, while removing many of the governance, bias assessment, and public reporting requirements from the 2024 version.
The Chatbot Safety Act (House Bill 26-1263, signed July 1, 2026) imposes obligations on operators of conversational AI services accessible to the general public, including requirements to disclose that users are interacting with AI, estimate user age, protect minors from sexually explicit content and simulated emotional dependence, implement suicide and self-harm response protocols, and submit annual reports to the Colorado Attorney General. The law also prohibits chatbot outputs from being presented as equivalent to services provided by licensed health care, legal, or mental health professionals.
Consumer Communications. All disclosures and communications to consumers must use plain language, be accessible to consumers with disabilities, be available in languages in which the deployer ordinarily interacts with consumers, and be readable across all devices.
Multiparty Arrangements. “Midstream developers,” companies that integrate third-party ADMT models into their own products and sell them to others, must obtain and pass along all developer documentation from upstream providers to downstream deployers who use the product to make consequential decisions. The roles of other parties in multiparty arrangements, including ADMT vendors, will be a topic of discussion during the upcoming hearing.
Developer Obligations. Developers must provide deployers with meaningful, accurate information about their ADMT’s intended uses, known limitations and risks, monitoring instructions, and the categories of data used to train the system. Trade secrets may be withheld by developers, but the legal basis must be identified and sufficient alternative information provided to deployers.
Adverse Outcome Disclosures. When a deployer uses covered ADMT to produce an adverse outcome, the deployer must provide a written disclosure to the consumer within 30 days through at least two communication methods. The disclosure must include a plain language description of the decision, the ADMT’s role, principal reasons for the adverse outcome (including automatic denial factors, inferences drawn from personal data, and risk scores) and instructions for exercising consumer rights. The proposed rules provide sector-specific examples for financial services, housing, insurance, employment, and education. Importantly, the Colorado Attorney General will consider deployers that are already required to provide adverse action notices under the Equal Credit Opportunity Act or the Fair Credit Reporting Act as satisfying Colorado’s requirements through those existing notices, provided they also include the required ADMT-specific content. This addresses one of the open questions we flagged in our prior blog regarding whether Colorado would require additional notices beyond existing federal requirements.
Consumer Rights. Consumers may request the personal data used in a covered ADMT consequential decision, correct factually inaccurate personal data used by the ADMT in making a consequential decision, and request meaningful human review and reconsideration of any ADMT consequential decisions. Deployers must confirm receipt of requests within 10 days and complete meaningful human review within 45 days. Reviewers must be independent, possess relevant expertise, and have genuine authority to override the consequential decision by the ADMT. ADMT may not assist in the review. The proposed rules’ multi-factor commercial reasonableness framework begins to address the open question we raised in our prior blog about the “commercially reasonable” standard for human review, though concerns about its application in consumer lending remain. Where an adverse outcome constitutes a severe and irreversible denial of a basic human need, a company’s ability to provide meaningful human review is presumed to be commercially reasonable.
Chatbot Exemptions. Menu- or button-based and rule-based chatbots addressing only narrow, discrete topics are exempt if they cannot generate sexually explicit content or engage in dialogue about suicidal ideation or self-harm. Internal workforce-only deployments are also exempt.
Age Assurance. Operators must use commercially reasonable or generally accepted methods to estimate user age. Self-declarations by consumers alone are insufficient. Accepted methods include zero-knowledge proofs, facial recognition matched to government ID, and digital footprint assessment. Operators may not willfully disregard signals, including behavioral signals processed by the AI itself, that a user is a minor.
AI Disclosures. Operators must disclose to all users that they are interacting with AI and not a human. For minor users, a persistent visible disclaimer is required throughout the conversation. For all users, the disclosure must appear at the start of each day’s first interaction, at least once every three hours in a continuous interaction, and whenever a user asks whether the chatbot is human.
Minor User Protections. Prohibited engagement-maximizing features for minors include leaderboards, badges, login streaks, and features tied to session length. Privacy settings for minor accounts must default to the most protective setting, including defaulting to not retaining prior session information or using minor user data for model training.
Annual Report. Operators must submit a detailed annual report to the Colorado Attorney General by July 1, 2027, covering calendar year 2027, including user tier by monthly active users, crisis referral counts and accuracy metrics, suicide and self-harm protocol descriptions, age-estimation methodologies, and metrics on minor users encountering prohibited content.
As we noted in our prior blog (here), financial institutions and other consumer-facing businesses in financial services, insurance, employment, education, and housing should carefully assess whether their use of algorithmic or AI-assisted tools constitutes covered ADMT or conversational AI services. The proposed rules begin to answer several open questions from the new law, particularly around adverse outcome disclosure alignment with existing federal notice regimes and the factors governing commercial reasonableness for meaningful human review. Many uncertainties remain, however — notably around enforcement timing given the pending litigation challenging the 2024 law and the Attorney General’s agreement to stay enforcement until regulations are finalized and the court addresses the plaintiffs’ preliminary injunction motion.
We believe that the financial services industry should strongly consider commenting on these proposed rules, because they contain a number of provisions that we expect will be difficult to operationalize or which may lead to highly negative outcomes for financial services companies and their customers. In particular:
We will continue to monitor the Attorney General’s rulemaking efforts under these laws.
Kim is a partner in the firm’s Privacy + Cyber Practice Group, where she is a privacy and data security attorney, who also assists companies with data breach prevention and response, including establishing effective security programs prior to a data breach and the
Kim is a partner in the firm’s Privacy + Cyber Practice Group, where she is a privacy and data security attorney, who also assists companies with data breach prevention and response, including establishing effective security programs prior to a data breach and the assessment of breach response obligations following a breach.
Chris is the co-leader of the Consumer Financial Services Regulatory practice at the firm. He advises financial services institutions facing state and federal government investigations and examinations, counseling them on compliance issues including UDAP/UDAAP, credit reporting, debt collection, and fair lending, and defending…
Chris is the co-leader of the Consumer Financial Services Regulatory practice at the firm. He advises financial services institutions facing state and federal government investigations and examinations, counseling them on compliance issues including UDAP/UDAAP, credit reporting, debt collection, and fair lending, and defending them in individual and class action lawsuits brought by consumers and enforcement actions brought by government agencies.
Taylor focuses her practice on providing regulatory advice on matters related to federal and state consumer protection, consumer finance, and payments laws, including those that apply to payment cards, lines of credit, installment loans, electronic payments, online banking, buy-now-pay-later transactions, retail installment contracts…
Taylor focuses her practice on providing regulatory advice on matters related to federal and state consumer protection, consumer finance, and payments laws, including those that apply to payment cards, lines of credit, installment loans, electronic payments, online banking, buy-now-pay-later transactions, retail installment contracts, rental-purchase transactions, and small business loans.
Troutman Pepper Locke helps clients solve complex legal challenges and achieve their business goals in an ever-changing global economy. With more than 1,600 attorneys in 30+ offices, the firm serves clients in all major industry sectors, with particular depth in energy, financial services, health care and life sciences, insurance and reinsurance, private equity, and real estate. Learn more at troutman.com.
In addition to cookies that are necessary for website operation, this website uses cookies and other tracking tools for various purposes, including to provide enhanced functionality and measure website performance. To learn more about our information practices, please visit our Privacy Notice.