Colorado's revised AI law is a documentation test worth passing
Senate Bill 26-189 turns AI compliance into a question of evidence, and organisations that record decisions as they happen will be ready before 1 January 2027.

Colorado's revised AI Act is a documentation test, and organisations that record their AI decisions as those decisions happen will pass it. On 14 May 2026 the Governor of Colorado signed Senate Bill 26-189, a reworked state AI law built around pre-use consumer notices, adverse-outcome explanations, meaningful human review and developer documentation, taking effect on 1 January 2027. Underneath the drafting, every one of those duties is a demand for evidence. We think regulated firms should welcome that, because evidence is precisely what well governed AI should already be producing.
What did Colorado actually sign into law on 14 May 2026?
Senate Bill 26-189 is a revised version of Colorado's state AI Act, signed by the Governor on 14 May 2026 and taking effect on 1 January 2027. As the law firm Norton Rose Fulbright set out in its analysis of the statute, the revised framework centres on four commitments: consumers must be told before an AI system is used on them, adverse outcomes must be explained, consequential decisions must carry meaningful human review, and developers must supply documentation for their systems. Colorado already had a state AI law on the books, and this revision shows the direction of travel: fewer abstract principles, more concrete paperwork.
Why do we read this as a documentation test rather than a restriction?
Because none of the four pillars tells an organisation which model to use or forbids a use case; each one asks whether you can show what your system did and who checked it. A pre-use notice requires you to know, in advance and in writing, where AI touches a consumer. An adverse-outcome explanation requires you to say why a specific decision went the way it did. Meaningful human review requires proof that a person genuinely intervened. Developer documentation requires the supplier to put its claims on paper. A firm can satisfy all four without changing a single model, provided its records are complete, contemporaneous and trustworthy. That is a test of engineering discipline, not of legal creativity.
How do you produce an adverse-outcome explanation you can stand behind?
You produce it from a record that was written at the moment of the decision, not assembled afterwards from log fragments and recollection. This is why we built the Open Audit Record into our operating system as a core subsystem rather than an optional extra. Every action a model takes inside Mickai is cryptographically signed as it happens, the signatures are post-quantum secure, the chain is tamper-evident, and the whole record can be verified offline without reference to us or to any third party. When a consumer asks why an outcome went against them, the answer is drawn from a sealed sequence showing what was asked, what was returned and who authorised the result.
The difference matters most under pressure. An organisation reconstructing a decision months later, from systems run by several vendors, is effectively asking a regulator to trust its memory.
“An explanation drawn from a signed record is evidence. An explanation drawn from memory is a hope.”
What does meaningful human review actually require?
It requires the system to make human intervention unavoidable and provable, not merely available. Inside our operating system, sensitive actions are gated twice before they run. First, our cooperative multi-model consensus substrate requires specialist sovereign models to agree before a sensitive action proceeds, which catches the confident single-model error that so often produces an adverse outcome. Second, designated actions require voice-biometric confirmation from an authorised person, so the human in the loop is a specific, identified individual rather than a checkbox. Both the machine consensus and the human confirmation are themselves written to the Open Audit Record, which means the review Colorado asks for is not asserted, it is recorded.
Does on-premise deployment matter for a US state law?
Yes, because control of the evidence follows control of the infrastructure. Mickai is a Sovereign Intelligence Operating System that runs entirely on the customer's own hardware, on-premise and, where required, fully air-gapped. That has two consequences for a statute like Colorado's. Regulated data stays inside the organisation the law actually governs, rather than moving through a remote provider's environment in another jurisdiction. And the audit record needed to satisfy an explanation or review duty is held by the organisation itself and verifiable offline, so a supplier outage, a contract dispute or a legal demand served on someone else's cloud cannot separate a firm from its own compliance evidence. A hardware-held root of trust anchors the whole arrangement to the machine in the building, not to a login.
How should organisations prepare before 1 January 2027?
Start now, because contemporaneous records cannot be created retroactively; every consequential decision made before your logging is in place is a decision you may one day have to explain from memory. We suggest a short, concrete sequence.
- Map every point where an AI system touches a consumer or a consequential decision, and draft the pre-use notices for each.
- Decide, per decision type, what a defensible adverse-outcome explanation must contain, then check whether your current systems capture those facts at decision time.
- Turn human review from policy into mechanism: name the reviewers, gate the actions, and record each intervention.
- Ask every AI supplier for developer documentation now, and treat an inability to provide it as a due diligence finding.
- Prefer architectures where the data, the models and the audit records all stay on infrastructure you control.
We built for this shape of regulation deliberately. Mickai carries 87 studios on one operating system, ten of them production ready at launch and 77 in development, and every studio writes to the same Open Audit Record under the same consensus and gating rules, so the compliance posture does not fragment as adoption spreads. The underlying architecture is the subject of 104 filed UK patent applications across 2,340 claims held by Mickai LTD, although the practical point is simpler than the filings: a law that asks for evidence is easy to meet when your operating system never stops producing it.
Frequently asked questions
When does Colorado's revised AI Act take effect?
It takes effect on 1 January 2027. The Governor of Colorado signed Senate Bill 26-189 on 14 May 2026, which leaves organisations the remainder of 2026 to prepare their notices, explanation processes and human review controls.
What does Senate Bill 26-189 require?
It requires pre-use consumer notices, explanations for adverse outcomes, meaningful human review of consequential decisions and documentation from developers, as set out in the analysis published by Norton Rose Fulbright. In practice, each duty depends on records created at the time a decision is made.
What is the Open Audit Record?
The Open Audit Record, or OAR, is the subsystem of our operating system that cryptographically signs every action as it happens. The signatures are post-quantum secure, the record is tamper-evident, and it can be verified offline, which makes it suitable evidence for explanation and review duties such as Colorado's.
Can an air-gapped system still meet documentation duties?
Yes. Because the Open Audit Record is verifiable offline, a fully air-gapped deployment produces the same signed evidence as a connected one. Documentation does not require a network connection; it requires a trustworthy record held by the organisation the law governs.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on-premise and air-gapped where required. Every action is signed to the Open Audit Record, sensitive steps are gated by multi-model consensus and voice-biometric confirmation, and the system operates fully offline. It carries 87 studios on one operating system, with ten production ready at launch and 77 in development, and its architecture is the subject of 104 filed UK patent applications across 2,340 claims, filed rather than granted, held by Mickai LTD.