The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding. If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit. The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies. The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data. The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually. The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer. The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor. The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information. The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
The act repeals limited purpose fee-for-service contracts for: the career pathways program, the multidisciplinary health-care provider access training program, and the career and technical education and apprenticeship programs alignment, on June 30, 2028; and cybersecurity and distributed ledger technologies and the food systems advisory council, on June 30, 2026. The act repeals, on June 30, 2028, the multidisciplinary health-care provider access training program, the career pathways program, and the state apprenticeship agency's career and technical education and apprenticeship programs alignment requirement.(Note: This summary applies to this bill as enacted.)
The act requires the state treasurer to transfer any unexpended and unencumbered money remaining in the public safety communications revolving fund at the end of a fiscal year to the public safety communications trust fund (trust fund). The act clarifies that the primary purpose of the money in the trust fund is to support the digital trunked radio system (DTRS) by acquiring and maintaining public safety communications systems and equipment for use by the office of public safety communications (office), state departments, and other users of the system. The money in the fund may also be used for the payment of maintenance expenses of the office, state departments, and other users related to the DTRS, including the cost of leased or rented equipment, infrastructure maintenance, tower lease costs, payments to local governmental entities for radio communications systems, or payments related to public safety radio systems.(Note: This summary applies to this bill as enacted.)
Current law requires an amount equivalent to the recorded depreciation or amortization of an information technology asset acquired, repaired, improved, replaced, renovated, or constructed with an appropriation from the information technology capital account in the capital construction fund based on the depreciation period (information technology annual depreciation-lease equivalent payment) to be credited and transferred to the information technology capital account within the capital construction fund. Current law also requires the state treasurer to transfer any unappropriated balances in the information technology capital account or any otherwise unexpended and unencumbered money remaining in the information technology capital account at the end of a fiscal year to the general fund. The act prohibits the state treasurer from transferring any money that was transferred, credited, or paid into the information technology capital account as an information technology annual depreciation-lease equivalent payment back to the general fund at the end of a fiscal year, for state fiscal years commencing on or after July 1, 2026.(Note: This summary applies to this bill as enacted.)
The act requires that the state treasurer make the following transfers of money on July 1, 2026:$131,514,555 from the general fund to the capital construction fund;$3,420,943 from the general fund to the information technology capital account in the capital construction fund;$500,000 from the general fund exempt account to the capital construction fund;$1,748,863 from the community impact cash fund to the information technology capital account in the capital construction fund;$587,318 from the motor carrier safety fund to the information technology capital account in the capital construction fund to be used for a records utilization upgrade for the Colorado state patrol; and$1,976,782 from the motorcycle operator safety training fund to the information technology capital account in the capital construction fund to be used for a records utilization upgrade for the Colorado state patrol.(Note: This summary applies to this bill as enacted.)
The act adds the Trinidad correctional facility, the Arkansas Valley correctional facility, and the Arrowhead correctional facility to the list of correctional facilities where the department of corrections may install broadband infrastructure. The act extends the repeal date of the broadband infrastructure cash fund to July 1, 2028.(Note: This summary applies to this bill as enacted.)
The act prohibits using an automated driving system to drive a commercial motor vehicle unless an individual who holds a commercial driver's license is in the vehicle, monitors the vehicle's driving, and intervenes, if necessary, to avoid illegal or unsafe driving. The individual must be in the driver's seat if hazardous materials are being transported. The penalty is $1,000 for a first offense, is $2,000 for a second offense, and doubles for each subsequent offense. The act does not apply to a light-duty vehicle or a truck-mounted attenuator. The prohibition is repealed September 1, 2031. The chief of the Colorado state patrol will analyze the act's effects on commercial vehicle safety on highways. By November 1, 2030, the chief of the Colorado state patrol will issue a report to the relevant committees of the house of representatives and senate. The report must make recommendations as whether to continue the prohibition and, if continued, any recommended legislation to improve the prohibition. For the 2026-27 state fiscal year, $14,357 is appropriated to the department of revenue from the Colorado DRIVES vehicle services account in the highway users tax fund to implement the act.(Note: This summary applies to this bill as enacted.)
In 2024, the general assembly enacted Senate Bill 24-205, which created consumer protections in interactions with artificial intelligence systems. The act repeals and reenacts those provisions with new requirements regarding the use of automated decision-making technology in consequential decisions. The act defines an 'automated decision-making technology' (ADMT) as a technology that processes personal data and uses computation to generate output, including predictions, recommendations, classifications, rankings, scores, or other information that is used to make, guide, or assist a decision, judgment, or determination concerning an individual. The act defines a 'consequential decision' as a decision that relates to an individual's access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health-care services, or essential government services and public benefits. The act requires the developer of an ADMT (developer) that is used to materially influence a consequential decision (covered ADMT), starting January 1, 2027, to provide a deployer of a covered ADMT (deployer) with technical documentation describing the covered ADMT's intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. Developers must notify deployers of material updates or modifications to the covered ADMT. Both developers and deployers are required to retain records necessary to demonstrate compliance with the act for at least 3 years. The act establishes consumer notice requirements, mandating that deployers provide clear and conspicuous notice to consumers at the point of interaction with a covered ADMT. A deployer is required to provide a consumer with a plain language description of a covered ADMT's role within 30 days after the covered ADMT makes a consequential decision that results in an adverse outcome for the consumer. The attorney general must adopt rules to clarify these post-adverse outcome disclosure requirements by January 1, 2027. Consumers have the right to request personal data and correction of factually incorrect personal data used by a covered ADMT. The act also grants consumers the right to request meaningful human review and reconsideration following a covered ADMT making a consequential decision resulting in an adverse outcome. The attorney general is directed to enforce the act through the 'Colorado Consumer Protection Act', and a violation of the act is deemed a deceptive trade practice. Before initiating an action before January 1, 2030, the attorney general must provide the developer or deployer with a 60-day notice and opportunity to cure the alleged violation, if a cure is deemed possible. The act does not create a new private right of action but establishes how fault is allocated between developers and deployers in civil actions alleging unlawful discrimination under existing law. Specified entities are exempted from the requirements of the act to the extent the entities comply with other legal obligations.(Note: This summary applies to this bill as enacted.)
The bill prohibits a government entity from accessing a database that reveals an individual's or a vehicle's historical location information, subject to certain exceptions. The bill prohibits a government entity from sharing historical location information with third parties or government agencies outside their jurisdiction, subject to certain exceptions, and makes historical location information not a public record for the purposes of the "Colorado Open Records Act".The bill requires a government entity that collects historical location information to adopt a policy to maintain compliance with the provisions of the regulatory scheme.An enforcement action is created for the attorney general to enforce the provisions of the bill. Historical location information obtained in violation of the prohibitions of the bill are inadmissible in trial.(Note: This summary applies to this bill as introduced.)