The European Union’s Artificial Intelligence Act and Colorado’s Artificial Intelligence Act mark the first-ever comprehensive AI laws in the EU and US.
Both laws have extraterritorial effects. Colorado’s, adopted by the governor on May 17, applies to developers and deployers of high-risk AI systems doing business in Colorado, potentially covering out-of-state businesses providing AI products or services to consumers in Colorado. The EU law, approved by the EU council on May 21, applies to developers, deployers, importers, distributors, and manufacturers of AI systems within the EU, as well as to organizations outside the EU if they place AI products on the market in the EU or if the outputs of their AI products are used by individuals within the EU.
Both laws primarily target the responsible development and deployment of high-risk AI systems. Colorado’s AI Act emphasizes preventing algorithmic discrimination, particularly in societal domains such as education, employment, finance, healthcare, housing, and insurance. In contrast, the EU’s law also addresses health, safety, and fundamental rights risks, including discrimination, for high-risk AI systems used for profiling, biometric analysis, employment decisions, and access to credit, healthcare, and insurance.
Significant responsibilities are imposed on developers or providers of high-risk AI systems under both laws. Colorado defines developers as those who develop or intentionally and substantially modify an AI system. Meanwhile, the EU extends this responsibility to those who brand or significantly modify an existing high-risk AI system, or elevate its risk through changes.
Transparency and disclosure obligations are integral to both laws. Developers in Colorado are required to provide general statements, summaries of training data, and documentation on various aspects of high-risk AI systems. They must also publicly disclose their types and risk management approaches. EU providers must offer sufficient transparency for deployers to effectively interpret and use outputs, including providing details on system capabilities, performance, and oversight measures.
Both regulations emphasize data governance. Colorado focuses on developers disclosing data governance, whereas the EU mandates detailed governance practices, requiring providers to ensure alignment of design choices, manage data collection and preparation processes, and implement measures to detect, prevent, and mitigate biases. EU providers must also implement risk and quality management systems, perform conformity assessments, and fulfill registration obligations.
Deployers also have stringent obligations. Both laws require informing consumers about significant AI-related decisions and managing discrimination risks. Colorado mandates annual impact assessments and incident reporting to the attorney general for any algorithmic discrimination. The EU requires certain deployers to conduct fundamental rights impact assessments and promptly inform relevant parties of any detected risks.
Furthermore, Colorado demands that deployers develop a risk management program based on established frameworks such as that provided by the National Institute of Standards and Technology. EU AI deployers have to ensure strict adherence to provider instructions, maintain data quality, monitor systems, comply with data protection laws, and document system use.
The EU and Colorado’s AI Acts provide more than regulatory mandates; they offer a structured path towards trustworthy AI. By adhering to these guidelines, companies can responsibly develop and deploy AI systems while gaining insights into future legislative trends. For more detailed comparisons and implications, refer to the full article on Bloomberg Law.