Policy + CO Readiness
$500 project
The starter step — your policy and the notices the law requires, in writing.
- Bilingual AI use policy
- Colorado ADMT Act notices & disclosures
- Human-review + data-correction steps
- Vendor / tool guardrails
Use AI with confidence — and stay on the right side of the rules. If you handle customer financial data — tax, bookkeeping, insurance — the FTC Safeguards Rule applies to you today. Colorado’s new AI law is the next beat, with a compliance date of January 1, 2027. We make both simple and plain-language, in English or Spanish.
Adopt AI without second-guessing. Clear policies and guardrails let your team move fast — no more “are we even allowed to do this?” hesitation.
Avoid the expensive surprises — a data leak, a discrimination claim from an AI hiring tool, or a required notice that never went out. We put the safeguards and required notices in first.
Enforceable today — the FTC Safeguards Rule (GLBA). If your business handles customer financial information — tax preparation, bookkeeping and accounting, insurance, lending — federal law already requires a written information-security plan, a person responsible for it, and safeguards like access controls and vendor oversight. This is not a 2027 problem; it applies right now.
Coming next — Colorado’s ADMT Act (SB 26-189, compliance date January 1, 2027) has no small-business or employee-headcount exemption. If your business operates in Colorado and uses AI or other automated technology to materially influence a consequential decision — including hiring, compensation, lending, housing, insurance, or health care — the notice, disclosure, human-review, and data-correction duties apply regardless of your size. Limited sector safe harbors (for example, HIPAA and insurance) do not cover employment decisions. We handle both, end to end.
Full guide: every Colorado AI & technology law, in plain language →
This is general information, not legal advice — confirm your specific situation with a Colorado-licensed attorney.
Start with the piece the IRS reminds you about at every PTIN renewal: a written information security plan (WISP). We build yours with you — bilingual, flat $595, delivered in 7 days.
See the WISP packageAny Colorado business that uses AI in decisions affecting people — hiring, lending, housing, health care, insurance — or any owner who wants AI set up safely before a mistake gets expensive.
Fixed-fee and transparent, a ladder you climb one step at a time: the $500 policy project puts your guardrails and required notices in writing, the $1,500 assessment adds a full scored review of your exposure, and a monthly plan keeps it all current. Prices are starting points.
$500 project
The starter step — your policy and the notices the law requires, in writing.
$1,500 assessment
The full picture — a scored, plain-language review of your AI use and exposure, with a prioritized roadmap.
$300 /mo
The ongoing step — stay current as the law and tools change. Three tiers, detailed below.
Once you are set up, a flat monthly plan keeps you compliant as the rules change. Pause anytime; pay yearly and save about 17%.
$300/mo
Stay current — an annual re-check plus alerts when the rules move.
$700/mo
Quarterly re-check, and we update your policies and notices for you when rules change.
$1,500/mo
Concierge — all applicable rules covered, your own point person, and fast incident support.
$20,000 maximum penalty per violation under Colorado’s AI law (the ADMT Act, SB 26-189). Colorado SB 26-189, 2026
63% of AI-breached organizations had no AI governance policy at all. IBM Cost of a Data Breach, 2025
Jan 1, 2027 compliance deadline for Colorado’s new AI law (the ADMT Act). Colorado SB 26-189, 2026
ClunasCo provides compliance enablement, not legal advice. For legal questions about your specific situation, consult a Colorado-licensed attorney.
Book a free 30-minute discovery call. Plain language, in your language, no obligation.