Colorado AI Act vs NYC LL144: the short answer
Colorado AI Act (SB 24-205) is regulatory and applies to Developers + deployers of high-risk AI systems used to make consequential decisions for Colorado consumers (employment, lending, housing, insurance, healthcare, legal services, education, government services). NYC Local Law 144 (Automated Employment Decision Tools) is sectoral and applies to Employers + employment agencies using automated employment decision tools (AEDTs) to substantially assist or replace discretionary decisions on New York City residents. The practical tension is that the first US state AI act versus the first US city AI audit mandate, and which one actually bites for an employer.
They are not substitutes. Across the fifteen governance dimensions compared here, 8 are addressed substantively by both, 3 are materially stronger in Colorado AI Act, and 0 are materially stronger in NYC LL144. Treating either as a superset of the other is the most common and most expensive mistake.
At a glance
Colorado AI Act (SB 24-205)
Type: Regulatory. Jurisdiction: Colorado, United States. In force: February 1, 2026. Exposure for getting it wrong: Unfair trade practice under Colorado Consumer Protection Act; up to USD 20,000 per violation. Best suited to: Companies making consequential decisions affecting Colorado residents
NYC Local Law 144 (Automated Employment Decision Tools)
Type: Sectoral. Jurisdiction: New York City, United States. In force: Enforcement began July 5, 2023. Exposure for getting it wrong: USD 500 - USD 1,500 per violation per day. Best suited to: Employers and HR-tech vendors making hiring or promotion decisions in NYC
The penalty asymmetry is usually what decides sequencing. Colorado AI Act carries legal consequences and NYC LL144 does not, so Colorado AI Act sets your deadline while NYC LL144 sets your method.
Where the work genuinely overlaps
These are the dimensions both frameworks address substantively, which means one piece of evidence can often satisfy both. This is where a combined programme saves real effort rather than just feeling tidy.
Transparency + disclosure. Colorado AI Act (C.R.S. 6-1-1703(4)): Section 6-1-1703(4) deployer notice to consumers before / after consequential decision; explanation right. NYC LL144 (5-302; 5-303): Public summary of bias audit on employer site; written notice to candidates 10 business days in advance.
Human oversight + intervention. Colorado AI Act (C.R.S. 6-1-1703(4)(b)): Section 6-1-1703(4)(b) consumer right to correction + appeal opportunity, implying human review path. NYC LL144 (Local Law 144 Sec. 1): Tool must not be sole basis under broader EEOC guidance; LL144 itself constrains automated tools that substantially assist decisions.
Post-market monitoring + drift. Colorado AI Act (C.R.S. 6-1-1703(2)(c)): Section 6-1-1703(2)(c) annual impact assessment; ongoing review for algorithmic discrimination. NYC LL144 (5-301(a)): Annual bias audit required before continued use; substantial modification triggers re-audit.
Vendor + third-party risk. Colorado AI Act (C.R.S. 6-1-1702(2)(b)): Section 6-1-1702 developer obligations flow to deployers via documentation requirements; deployer relies on developer disclosures. NYC LL144 (5-301; 5-302): Employer may rely on vendor bias-audit if the employer can show the AEDT was independently audited; LL144 documentation flows from vendor.
Audit trail + documentation. Colorado AI Act (C.R.S. 6-1-1703(2)(c)): Section 6-1-1703(2)(c) impact assessment documentation retained for at least 3 years. NYC LL144 (5-301; 5-302): Independent annual bias audit + public summary, available for at least 6 months from posting.
Bias + fairness testing. Colorado AI Act (C.R.S. 6-1-1701(1)): Core duty: avoid algorithmic discrimination defined in Section 6-1-1701(1). NYC LL144 (5-301): Core obligation: annual bias audit computing selection-rate / impact-ratio by sex, race / ethnicity, and intersectional categories.
The caveat worth stating: overlapping subject matter does not mean interchangeable evidence. Colorado AI Act and NYC LL144 frequently want the same control documented to a different standard of proof, so plan to write once and format twice.
Where they diverge, and why it matters
Stronger in Colorado AI Act
Governance + accountability. Colorado AI Act is explicit here (C.R.S. 6-1-1703(3)): Section 6-1-1703(3) deployers must implement a risk-management policy and program covering high-risk AI. NYC LL144 is mentioned only by comparison.
Risk management process. Colorado AI Act is explicit here (C.R.S. 6-1-1702(2); 6-1-1703(2)): Sections 6-1-1702(2) developer impact summary + 6-1-1703(2) deployer impact assessment annually + on substantial modification. NYC LL144 is mentioned only by comparison.
Incident + serious-incident reporting. Colorado AI Act is explicit here (C.R.S. 6-1-1703(7)): Section 6-1-1703(7) deployer must notify Attorney General within 90 days of discovering algorithmic discrimination. NYC LL144 is not addressed by comparison.
These gaps are the practical argument against treating either framework as complete on its own. If you adopt only Colorado AI Act, the NYC LL144-stronger dimensions above are the ones an auditor or regulator will find unaddressed.
What neither framework covers well
Worth knowing before you assume a compliance programme equals a control programme. Neither Colorado AI Act nor NYC LL144 addresses the following substantively:
Access control + security. Whether identity, access, encryption, key management, and infrastructure security are required.
Training + AI literacy. Whether staff training, AI literacy, or operator competence is required.
These are not oversights so much as scope boundaries. They still have to be handled by someone, and in practice that falls to the platform layer rather than the framework.
Which to tackle first
Start with Colorado AI Act (SB 24-205). It is regulatory, it is in force from February 1, 2026, and non-compliance carries Unfair trade practice under Colorado Consumer Protection Act; up to USD 20,000 per violation. Deadlines and penalties dictate sequencing regardless of which framework is intellectually tidier.
Then layer NYC Local Law 144 (Automated Employment Decision Tools). Because it is sectoral, it earns its place by making the first one repeatable and evidenced rather than by adding a separate obligation. Teams that invert this order tend to build an elegant management system and still miss a statutory deadline.
The efficient path is to scope NYC LL144 around the evidence Colorado AI Act already forces you to produce, rather than running two programmes side by side.
How Areebi maps to Colorado AI Act and NYC LL144
Areebi does not certify you against either framework. What it does is produce the runtime evidence both of them ask for, from the same control plane, so the overlap above becomes real rather than theoretical.
For Colorado AI Act: Deployer impact-assessment template included; satisfies 6-1-1703(2)(c). Consumer-notice templates available for 6-1-1703(4) disclosures. Algorithmic-discrimination monitoring dashboards align with annual review duty. Vendor documentation aggregator helps deployers rely on developer disclosures.
For NYC LL144: Bias-audit evidence pack generation for HR tool deployments. Candidate notice + RFI workflow templates included. Independent audit-friendly data exports. Audit-log retention beyond LL144 6-month minimum.
The common thread is that both frameworks want to know what your AI systems actually did, not what your policy said they should do. That is an operational logging and enforcement problem before it is a documentation problem.
Frequently Asked Questions
Does complying with Colorado AI Act mean we comply with NYC LL144?
No. Of the fifteen dimensions compared, 0 are materially stronger in NYC LL144. Colorado AI Act compliance is useful evidence toward NYC LL144 but does not satisfy it.
Which of Colorado AI Act and NYC LL144 is legally binding?
Colorado AI Act (SB 24-205) is regulatory in Colorado, United States, in force from February 1, 2026, with exposure of Unfair trade practice under Colorado Consumer Protection Act; up to USD 20,000 per violation. NYC Local Law 144 (Automated Employment Decision Tools) is sectoral and carries no direct statutory penalty, though it is increasingly a procurement requirement.
What do Colorado AI Act and NYC LL144 agree on?
8 of fifteen dimensions are addressed substantively by both, notably transparency + disclosure, human oversight + intervention, post-market monitoring + drift, vendor + third-party risk. Evidence produced for one can usually be reused for the other, though the required standard of proof often differs.
Is there anything neither Colorado AI Act nor NYC LL144 covers?
Yes. Access control + security, Training + AI literacy are addressed weakly or not at all by both. Those obligations do not disappear; they simply are not framework-driven, and usually land on the platform or engineering team.
Which should we implement first, Colorado AI Act or NYC LL144?
Colorado AI Act, because it is enforceable from February 1, 2026 and carries Unfair trade practice under Colorado Consumer Protection Act; up to USD 20,000 per violation. Scope the second framework around the evidence the first already forces you to produce.
How current is this comparison?
Every cell is tied to a specific clause reference and is maintained alongside the full crosswalk of twelve frameworks across fifteen dimensions, which is published openly under CC BY 4.0. Source texts: https://leg.colorado.gov/bills/sb24-205 and https://rules.cityofnewyork.us/wp-content/uploads/2023/04/DCWP-NOA-for-Use-of-Automated-Employment-Decisionmaking-Tools-2.pdf.
Ready to switch from NYC LL144?
Migration support included
Get a personalized demo and see how Areebi compares for your specific requirements.