TL;DR: Colorado's revised ADMT rulemaking draft closes September 23, 2026 -- five days from today. Rule 6.6 introduces a named-data-source obligation: employers using AI in consequential employment decisions must list every data source by name, including third-party aggregators. The Colorado AI Act takes effect January 1, 2027. Three employer checks before the rule becomes enforceable.
The Colorado AI Act has been in rulemaking since it passed in 2024. Most employers have been watching from a distance, assuming the final rules would land somewhere reasonable and there would be time to adapt. That assumption is now running out of runway.
The Colorado Attorney General's revised ADMT rulemaking draft closes for public comment on September 23. Five days from today. The final rules are expected before the January 1, 2027 effective date -- which is 15 weeks away. And the draft contains one provision -- Rule 6.6 -- that most HR and compliance teams have not fully mapped to their vendor contracts.
What Rule 6.6 actually requires
Rule 6.6 in the revised draft addresses developer and deployer disclosure obligations for high-risk ADMT systems used in consequential employment decisions. The core requirement is this: when an employer deploys an AI system that substantially contributes to a consequential decision for a Colorado resident, that employer must be able to identify every data source the system relies on -- by name.
The "by name" requirement is the new element. Earlier versions of the rulemaking draft allowed references to categories of data ("background check information," "behavioral assessments," "professional history"). The September revised draft closes that door. If your AI hiring tool pulls from an Equifax Workforce Solutions database, a LinkedIn data licensing agreement, a resume parsing service, or a proprietary behavioral scoring dataset, Rule 6.6 requires that those sources be specifically identified in the employer's required disclosures.
This matters because most enterprise AI hiring tools are black boxes to the employer. The employer deploys a platform -- Workday, HireVue, a bespoke ATS with AI scoring, a third-party screening product -- and the platform's data pipeline is an implementation detail the vendor manages. Under Rule 6.6, that implementation detail becomes a legal disclosure obligation for the employer.
Rule 6.6 also covers third-party aggregators specifically -- not just primary data sources. An aggregator is an entity that compiles data from multiple sources and sells or licenses the compiled dataset. Background check vendors, workforce analytics platforms, and AI scoring services frequently use aggregated data without disclosing the upstream sources to the deploying employer. Under Colorado's revised draft, "we use a third-party aggregator for employment history verification" is not a compliant disclosure. The aggregator must be named, and the data categories it contributes must be disclosed.
Who ADMT covers -- and the extraterritorial reach
Colorado ADMT applies to consequential employment decisions for Colorado residents -- regardless of where the employer is headquartered. This extraterritorial reach is deliberate and mirrors the approach Colorado took with its privacy law. If you hire, evaluate, or terminate Colorado residents using AI that substantially contributes to the decision, the Colorado AI Act applies to you.
"Substantially contributes" is defined in the rulemaking draft to cover AI that produces a recommendation, score, ranking, or classification that the human decision-maker considers in reaching the final decision. An AI tool that screens out candidates before a human reviews the pool is substantially contributing to hiring decisions, even if a human makes the final offer.
Consequential employment decisions covered by ADMT include: initial hiring decisions, internal promotion and transfer decisions, compensation and benefits determinations, performance evaluation outcomes that affect employment status, and scheduling decisions that materially affect income. The breadth is intentional -- the AG rulemaking rejected narrower scoping that would have limited ADMT to hiring and termination only.
Why most employer AI contracts don't cover this yet
The practical compliance problem with Rule 6.6 is that most enterprise AI vendor contracts do not contain data source transparency obligations that match what the rule requires.
Standard AI SaaS agreements typically include a data processing addendum (DPA) covering how the vendor handles the employer's own data -- candidate records, employee data passed to the system -- but they do not typically include a disclosure obligation running in the other direction: what data the vendor's AI model uses to produce its outputs. A vendor's model may incorporate publicly licensed behavioral assessments, proprietary scoring datasets built from millions of historical hiring decisions, or data licensed from third-party aggregators. None of that appears in a standard DPA.
Some vendors have begun adding "model transparency" sections to enterprise agreements in response to state AI laws. But the disclosures are often categorical rather than named -- "our model uses behavioral and professional data" -- which will not satisfy Rule 6.6's named-source requirement. Employers who have not specifically negotiated named-data-source disclosure into their vendor contracts will need to go back to their vendors before January 1.
The meaningful human review standard
Rule 6.6 addresses data source disclosure, but it sits within a broader framework that includes a meaningful human review requirement. Under the ADMT rules, individuals subject to a consequential AI employment decision must be able to request human review -- and that review must be meaningful.
The revised draft defines meaningful review as: a reviewer with actual authority to override the AI output, access to the basis for the output (not just the conclusion), and a documented review process with a timeline for response. A review mechanism that routes the request to the same AI system is not compliant. A review that gives the human reviewer no information about why the AI scored the candidate as it did is not compliant.
For employers whose AI hiring tools produce opaque scores -- "candidate ranked 3rd of 47 applicants" with no explainability layer -- the meaningful review standard requires either a new explainability layer from the vendor or a manual review process that reconstructs the reasoning independently.
This is where the Rule 6.6 data source obligation and the meaningful review obligation intersect: a reviewer cannot meaningfully evaluate an AI output if they do not know what data the AI used to produce it. The disclosure and review obligations are designed to work together, and a vendor contract that addresses one but not the other leaves a compliance gap.
3 employer checks before January 1
1. Ask your AI hiring vendor for a complete named-data-source list.
Request a document from each vendor whose AI tools contribute to consequential employment decisions for Colorado residents. The request should ask specifically: what data sources does this AI system use to produce candidate scores, rankings, or recommendations -- by name? What third-party data aggregators are in the pipeline? When were those data licenses last reviewed?
If the vendor cannot provide this at all, that is a Rule 6.6 compliance risk you cannot paper over with a generic DPA addendum. If the vendor provides a categorical list, push for named sources. The vendor's legal and compliance team will know what Rule 6.6 requires if they have been tracking Colorado ADMT. If they have not been tracking it, that itself is a signal about the vendor's governance readiness for January 1.
2. Map the gap between what your vendor discloses and what Rule 6.6 requires.
Once you have the vendor's data source list, compare it against the Rule 6.6 named-source standard. Look specifically for: data licensed from third-party aggregators that are not named, behavioral scoring datasets whose origin is described categorically rather than specifically, and historical hiring data used to train the model (whose provenance may be unclear even to the vendor).
Document the gap. This documentation matters both for your own compliance posture and as the basis for a vendor amendment conversation. The named-source obligation runs to the employer as deployer, not to the vendor -- so even if the vendor refuses to disclose, the employer remains the responsible party under Colorado ADMT.
3. Verify your human review mechanism meets the meaningful standard before October.
The meaningful review definition in the revised draft is specific enough that most boilerplate "appeal your AI decision" links in candidate-facing communications will not satisfy it. Before December, test your review mechanism against the four elements in the AG's definition: reviewer authority, access to basis, documented process, response timeline.
If your current vendor provides no explainability layer, request a feature roadmap conversation before November 1. Vendors who have not built explainability into their product by January 1 will be unable to support meaningful review for Colorado residents without a manual workaround -- and that workaround needs to be documented and operational before the effective date.
For the broader vendor contract framework around AI employment tools, see the agentic AI vendor contract clauses guide and the AI vendor due diligence checklist. For how Colorado ADMT intersects with the federal FCRA on AI screening, see the FCRA AI hiring vendor compliance analysis.
Related Reading
- NYC Local Law 144: automated employment decision tool compliance guide
- FCRA and AI hiring: vendor compliance checklist for 2026
- Workday AI lawsuit: what employer liability means for your AI hiring stack
- Colorado AI Act SB 205: employer guide to ADMT obligations
- EEOC AI hiring guidance: what the agency said in 2026
- AI vendor due diligence checklist 2026
- Agentic AI vendor contract clauses: what to add in 2026
