InvestNot yet confirmed elsewhere1 publisher3 min readPublished
Colorado's AI Act hands banks a January deadline to name every data broker
The amended law narrows to loan and account decisions, then demands disclosure up front, source-level explanation after a denial, and a correction path. The build lands on core vendors.
The Investor · Invest desk

What happened
- Colorado narrowed its AI Act to automated systems that materially influence consequential decisions, including loan and new account approvals, ahead of a January effective date.
- Banks using AI on Colorado customers must give clear and conspicuous disclosure before the decision is made.
- Where a model materially influenced a denial, the adverse action notice must tell the consumer how to request the system's name, its developer, and the data behind it.
Why it matters
- cost The engineering does not sit with compliance departments. It sits in core, lending and account-opening software, which banks rent, so the price arrives as vendor release schedules and contract...
- decision A bank on a third-party core now chooses between waiting for the vendor's automated compliance process and standing up its own request handling before January.
- precedent Colorado has written down what an AI explanation must contain, item by item. With California and Texas also active, that itemisation becomes the spec vendors build once and sell everywhere.
The hardest sentence in the statute is the one about naming. A denied consumer can demand that every data source be identified by name, including data brokers and intermediaries, along with the specific pieces of personal data used, a way to correct inaccurate data, and meaningful human review [7]. At a typical bank, none of those data relationships belong to the bank. Credit and account-opening decisions run through a core system, most likely from FIS, Fiserv or Jack Henry, with account-opening software such as Alloy's alongside it, and Frank Trotter, CEO of Battle Bank in Avon, Colorado, says all of the vendors banks use are using AI [9][17]. The list a Colorado bank hands a rejected applicant is therefore assembled out of its vendor's suppliers, and quite possibly its vendor's suppliers' suppliers [12]. Trotter expects the vendors to build automated processes for it [17].
Scott Kosnoff of Faegre Drinker told American Banker that the source-naming granularity is a big deal, and that data correction and meaningful human review may require new infrastructure [14]. That sits oddly beside the fact that AI decisioning software usually ships with explainability already in it: Trotter says he can open any denial in his own system and see every factor, an address that does not match a driver's license, or 20 Social Security numbers associated with one license, which reads as fraud [10]. The model is not the gap. The gap is the plumbing around it, an identity-checked request channel and a correction route that writes back into whatever the model consumed [13].
Trotter's own example shows why handing that detail over is uncomfortable. An explanation naming the fraud signal that fired tells whoever receives it exactly which check to defeat next time, and Trotter raised the risk of a criminal impersonating the applicant to get it [18].
The front-end obligation is cheaper, and still not free. Obrea Poindexter of Orrick says "clear and conspicuous" is contextual, and that nine times out of ten the disclosure will not sit in a footnote [1]. Kosnoff says the proposed regulations get specific: plain, straightforward language, readable on all devices including mobile, and no smaller than 12-point font in print [2]. That is a change to the application screen itself, made before the model is consulted rather than after it decides [4][11].
Regulation B already obliges a bank to say why it said no [5]. Colorado adds a second envelope inside the first, carrying instructions on how to ask for the system's name, its developer, and the categories and sources of data behind the outcome [6]. "The concept is fair," Trotter said. "If you've been denied for one reason or another, you should at least have the opportunity to know why" [8]. The bill for that fairness is a file format, an audit trail and a human reviewer, and it is due in January [3].
What to watch
- Whether FIS, Fiserv, Jack Henry and Alloy ship Colorado compliance features before January, and what they charge for them.
- The final regulations, especially whether the plain-language, mobile-readability and 12-point font specifics survive as drafted.
- Whether the by-name source requirement is read to reach a vendor's upstream data suppliers or stops at the vendor itself.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence52
- Adoption28
- Hype gap+12
- Incentives62
- Confidence54
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Obrea Poindexter, a partner at Orrick, said what "clear and conspicuous" means is contextual, and that nine times out of 10 the disclosure will not be in a footnote but presented so the consumer notices it.
ReportedSupportedSource: Obrea Poindexter, Orrick, to American Banker2 sources— create a free account to open themView cited source - [2]
Scott Kosnoff, partner at Faegre Drinker, said the proposed regulations add specifics: disclosures must use "plain, straightforward language," be readable on all devices including mobile, and printed disclosures must be in no less than 12-point font.
ReportedSupportedSource: Scott Kosnoff, Faegre Drinker, to American Banker2 sources— create a free account to open themView cited source - [3]
Colorado recently narrowed its AI Act, which is due to take effect in January, limiting the statute's scope to automated decision-making technology that materially influences "consequential decisions" including approvals for loans and new accounts.
- [4]
Financial institutions that use AI to make decisions must provide "clear and conspicuous" disclosure to any Colorado customers beforehand.
- [5]
Any time a bank denies a loan or account it already has to explain why and provide an adverse action notice under federal Regulation B.
- [6]
Under Colorado's new law, if an AI model materially influenced a denial, the bank must include instructions for the consumer to request additional information about the system used, including its name, its developer, and the types, categories and sources of personal data used.
- [7]
When a consumer makes that request, every data source must be identified by name, including data brokers and intermediaries; consumers have the right to ask for all specific pieces of personal data used in the decision, to be provided with a way to correct inaccurate data, and to obtain "meaningful" human review.
- [8]
Frank Trotter, CEO of Battle Bank in Avon, Colorado, said: "The concept is fair. If you've been denied for one reason or another, you should at least have the opportunity to know why. It's kind of a principle of credit: you get to ask the question."
- [9]
Trotter said that at most banks, credit and account opening decisions are made by a core banking system, most likely from FIS, Fiserv or Jack Henry, plus account opening software such as Alloy's.
- [10]
Banking software that uses AI in decision-making typically has explainability built in; Trotter said he can go into his system and see all the factors behind any denial, such as an address that does not match a driver's license, or 20 Social Security numbers associated with one driver's license, indicating fraud.
- [11]
The law attaches obligations at two separate points in a single application: a disclosure before the model is used, and a set of request instructions after an adverse decision.
- [12]
Because the deciding systems and their data feeds are supplied by third parties, the by-name source list a Colorado bank owes a rejected applicant must be sourced from its vendors and their upstream suppliers rather than from the bank's own records.
- [13]
Since decisioning software already exposes the factors behind a denial internally, the new infrastructure the law requires is the consumer-facing layer: a verified request channel, a correction route into the model's inputs, and a human reviewer.
- [14]
Kosnoff said the granularity of the Colorado law, particularly the need to identify every data source by name, is a big deal, and that the data correction and meaningful human review requirements may require building new infrastructure.
ReportedInsufficientSource: Scott Kosnoff, Faegre Drinker, to American Banker2 sources— create a free account to open themView cited source - [15]
Banks and their vendors may have to make significant changes to core, lending and new account-opening software.
ReportedInsufficientSource: American Banker2 sources— create a free account to open themView cited source - [16]
Even after being watered down, Colorado's AI Act remains one of the three most aggressive state AI laws, along with California's and Texas's.
- [17]
Trotter said "All the vendors we all use, use AI," and that these vendors will have to come up with automated processes for complying with the new Colorado law.
- [18]
Trotter pointed out a downside of sharing these decision details with consumers: a criminal could pretend to be the customer (the source's sentence is truncated at this point).
Sources
1 independent publisher whose own reporting we read for this story.
- americanbanker.comWhat Colorado's amended AI law means for banks
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.