Chatbot Safety Act · HB 26-1263

Colorado's chatbot law: does YOUR bot need to comply?

Colorado passed the nation's first standalone chatbot statute (signed May 29, 2026; operator duties start January 1, 2027). Short honest answer for most businesses: if your website chatbot answers questions about your hours, services, and prices, the law's definition likely does not cover it. Here is the actual test, what covered operators owe, and why building bots the safe way still matters.

The facts (verified against the enrolled bill)

  • HB 26-1263 was signed May 29, 2026; the act takes effect August 12, 2026, and operator duties begin January 1, 2027.
  • It covers "operators" of a conversational AI service: AI accessible to the public that PRIMARILY simulates human conversation — the target is companion-style AI, not business tools.
  • The enacted definition excludes routine customer-service and commerce bots. Where exactly the line sits is being clarified in the Attorney General's rulemaking now.
  • Enforcement runs through the Colorado Consumer Protection Act — the same act that carries civil penalties up to $20,000 per violation.

What covered operators owe

  • Disclose clearly that the user is talking to an AI, not a human.
  • Use commercially reasonable methods to estimate user age.
  • For known minors: extra protections — no engagement-reward mechanics, no sexually explicit content, no simulated emotional dependence.
  • Implement a response protocol for suicidal-ideation and self-harm prompts.
  • Never state or imply the bot's output is equivalent to licensed professional services (medical, legal, therapeutic).
  • File an annual report with the Colorado Attorney General.

The 3-question test for your business bot

  1. Does your bot primarily simulate open-ended human conversation and companionship — or does it answer questions about your business? A scoped customer-service bot points strongly to "not covered."
  2. Could a reasonable user treat it as a companion, confidant, or advisor rather than a service tool? Wellness bots, coaching bots, and anything conversational-for-its-own-sake sit closer to the line.
  3. Do minors realistically use it? Public-facing bots on consumer sites should think about the minor-protection duties even if coverage is unclear.

The honest part — and why we build to the standard anyway

We will not tell you your FAQ bot "must comply" — as enacted, it likely does not, and anyone selling panic is misreading the statute. But here is why every chatbot we build meets the law's core standards regardless: disclosing that users are talking to AI builds trust and costs nothing; routing self-harm language to the 988 crisis line is simply the right engineering; and never implying professional advice is already how a well-guardrailed bot should behave. If the AG rules later pull more bots into scope, ours are already there. That is what "law-aware by design" means on our chatbots page.

What we do

Every bilingual chatbot we build ships with AI disclosure, crisis-safe response routing, and professional-care disclaimers baked into the guardrails — in English and Spanish. Already have a bot someone else built? We run a fixed-fee chatbot compliance review (from $495): where it stands against HB 26-1263's standards, what to fix, and the config to fix it.

This page is general information verified against leg.colorado.gov as of July 12, 2026 — not legal advice, and the operator definition is subject to AG rulemaking. Confirm your specific situation with a Colorado-licensed attorney.

Ready to put AI to work?

Book a free 30-minute discovery call. Plain language, in your language, no obligation.