Skip to main content

By State / Colorado

Colorado AI Vendor Governance

AI vendors evaluated against the Colorado AI Act SB 24-205 — the first US comprehensive AI consumer protection law, effective February 1, 2026. Requires high-risk AI system classification, deployer + developer obligations, and impact assessments for consequential decisions.

Colorado — vendors with explicit state engagement, ranked by 4 state-relevant governance axes.

Edition: 2026-Q2State: COVendors: 30State-relevant axes: 4
By Stefan Efros, CEO & Founder, EFROSReviewed by Daniel Agrici, Chief Security Officer, EFROS
Reviewed by CSO ·

Why this state view

The Colorado AI Act SB 24-205 is the first US comprehensive AI consumer protection law. Vendors serving Colorado customers or developing AI for high-risk consequential decisions need to engage with the deployer-developer model. The Colorado AI Act is the leading indicator for what other state regimes will adopt.

Primary frameworks anchored

  • Colorado AI Act SB 24-205 (effective Feb 1, 2026)
  • Colorado Consumer Protection Act
  • NIST AI RMF 1.0 (anchor framework for Colorado AI Act compliance)

State-relevant scoring axes

Columns marked with an accent dot in the scorecard below are the axes most relevant to Colorado's regulatory frame. The state-relevance ranking in this view averages vendor performance across these axes only.

  • Colorado AI Act readiness
  • NIST AI RMF self-attestation
  • BAA / DPA available
  • Subprocessor list public
Colorado vendor scoring — state relevance descending. Columns relevant to Colorado regulatory frame are marked with an accent dot.
#VendorCO Rel.ScoreGradeBAAOpt-outUS ResSOC 2ISO 42001NIST AICO AI§1557SR 11-7ABA 512SubprocTC
1Abridge75(4/4)87AYesYesYesYesPartialPartialPartialYesN/AN/AYes5/5
2Thomson Reuters CoCounsel75(4/4)80BYesYesYesYesNoPartialPartialN/AN/AYesYes4/5
3FICO Falcon Fraud Manager + FICO Score AI75(4/4)80BYesYesYesYesNoPartialPartialN/AYesN/AYes4/5
4Microsoft 365 Copilot75(4/4)75BYesYesYesYesPartialPartialPartialPartialPartialPartialYes5/5
5Suki AI75(4/4)72BYesYesYesYesNoPartialPartialPartialN/AN/AYes4/5
6Lexis+ AI63(4/4)76BYesYesYesYesNoPartialNoN/AN/AYesYes4/5
7Westlaw Precision AI63(4/4)76BYesYesYesYesNoPartialNoN/AN/AYesYes4/5
8Harvey63(4/4)74BYesYesYesYesNoPartialPartialN/AN/AYesPartial3/5
9Zest AI63(4/4)74BYesYesYesYesNoPartialPartialN/AYesN/APartial3/5
10Upstart63(4/4)74BYesYesYesYesNoPartialPartialN/AYesN/APartial3/5
11Nuance DAX Copilot (Microsoft)63(4/4)70BYesYesYesYesNoPartialNoPartialN/AN/AYes5/5
12Salesforce Einstein / Agentforce63(4/4)69CYesYesYesYesNoPartialNoPartialPartialN/AYes5/5
13Glean63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
14Arctic Wolf63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
15Huntress63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
16eSentire63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
17Sophos63(4/4)69CYesYesYesYesNoPartialNoN/AN/AN/AYes4/5
18Unit2163(4/4)68CYesYesYesYesNoPartialNoN/APartialN/AYes4/5
19Ironclad AI50(4/4)63CYesYesYesYesNoNoNoN/AN/APartialYes4/5
20Anthropic Claude50(4/4)58CPartialYesPartialYesNoPartialNoN/AN/AN/AYes4/5
21Google Gemini for Workspace50(4/4)58CPartialPartialYesYesNoPartialNoN/AN/AN/AYes4/5
22OpenAI ChatGPT & API50(4/4)53DPartialPartialPartialYesNoPartialNoN/AN/AN/AYes4/5
23Hummingbird38(4/4)56CYesYesYesYesNoNoNoN/APartialN/APartial3/5
24ConnectWise38(4/4)50DPartialYesPartialYesNoNoNoN/AN/AN/AYes3/5
25Spellbook38(4/4)45DYesYesPartialPartialNoNoNoN/AN/APartialPartial2/5
26Heidi Health38(4/4)45DYesYesPartialPartialNoNoNoPartialN/AN/APartial2/5
27Notion AI25(4/4)33FNoPartialNoYesNoNoNoN/AN/AN/AYes3/5
28Otter.ai13(4/4)25FNoPartialNoYesNoNoNoN/AN/AN/APartial2/5
29Perplexity AI13(4/4)19FNoPartialNoPartialNoNoNoN/AN/AN/APartial2/5
30Meta Llama0(4/4)25FNoYesYesNoNoNoNoN/AN/AN/ANo2/5

How vendors score on Colorado's relevant axes

Yes / partial counts across the full 30-vendor pool, restricted to axes relevant to Colorado's regulatory frame. N/A axes are excluded from the applicable denominator.

CO AI

Colorado AI Act readiness

CO
Yes0/30 (0%)
Partial8/30 (27%)

NIST AI

NIST AI RMF self-attestation

CO
Yes0/30 (0%)
Partial21/30 (70%)

BAA

BAA / DPA available

CO
Yes22/30 (73%)
Partial4/30 (13%)

Subproc

Subprocessor list public

CO
Yes21/30 (70%)
Partial8/30 (27%)

Top 3 vendors on the Colorado-relevant axis subset

Buyer's guide for Colorado

For Colorado-deploying organizations, the highest-leverage axes are explicit Colorado AI Act engagement, NIST AI RMF anchoring (the framework Colorado AI Act references), and BAA/DPA scope for high-risk system contexts. Vendors that score 'No' on Colorado AI Act readiness require deployer-side documentation work.

Operationalize the scoring

Colorado AI Act for Healthcare Deployers

The Index tells you which vendors clear the bar for Colorado engagement. The companion resource tells you how to turn that selection into a deployable governance program with documented evidence.

Colorado AI Act for Healthcare Deployers →

Scoring as of 2026-05-13from public information (vendor trust portals, BAAs, SOC report cover pages, model cards, vendor documentation). Posture changes frequently — re-verify with the vendor's trust center before contract. State filter views surface vendors with explicit state engagement on the axes most relevant to that state's regulatory frame; they do not replace deployer-side state compliance work. Methodology: read the full methodology.

Turn the scoring into a deployable program

The Index tells you the posture. These engagements turn the posture into operational evidence for Colorado deployments.