From Sidhant Tamrkar | Product & Market Analysis

The FTC's Section 5 Theory Against Colorado's AI Law, and What Vendors Do Now

On this page

On 1 July 2026 the Federal Trade Commission voted 2-0 to propose a policy statement saying an AI company that quietly changes its outputs to satisfy a state law may be deceiving its users. It named Colorado. Colorado's replacement AI law, SB 26-189, still takes effect on 1 January 2027. Read side by side, the FTC AI policy statement and the Colorado law collide on far less ground than the coverage suggests, and the ground they share has one exit.

Key takeaways

  • The FTC statement is a proposal, not a rule. It was released on 1 July 2026, published in the Federal Register on 7 July, and closed for comment on 31 July. It creates no new obligation and preempts nothing on its own.
  • Colorado's SB 26-189 is mostly a process law. It requires documentation, notice, a 30-day adverse-outcome explanation, data correction, human review and 3 years of records. None of those duties tells a model what to output.
  • The real collision is one liability clause. The FTC objects that SB 26-189 still exposes developers to discrimination claims arising from customers' use, which it says pressures vendors to alter accurate outputs.
  • Disclosure satisfies both regulators. The FTC says clearly disclosed output adjustments avoid deception, and Colorado's law is built on disclosure. A vendor that documents every adjustment and its reason sits on the safe side of both.

The short answer

The FTC policy statement does not cancel Colorado's AI law. It is a non-binding proposal, and its preemption theory would have to win in court. SB 26-189 still governs covered automated decisions from 1 January 2027. Comply with Colorado's notice and review duties, and disclose any output adjustment you make, with its reason.

1 Jan 2027Date Colorado's SB 26-189 obligations begin, replacing the never-enforced 2024 AI Act. Source: Colorado General Assembly, 2026.
$20,000Maximum civil penalty per violation, enforced by the Colorado Attorney General alone. Source: ArentFox Schiff, May 2026.
2-0FTC vote to publish the proposed AI accuracy policy statement for comment. Source: FTC press release, 1 July 2026.

What the FTC AI policy statement actually says

The document is titled the Proposed Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems. It exists because of Executive Order 14365, signed on 11 December 2025. That order directed the FTC to explain how Section 5 of the FTC Act applies to state laws that require changes to the truthful outputs of AI models.

Section 5 prohibits unfair or deceptive acts or practices. The statement leans almost entirely on deception. Under the FTC's long-standing test, a practice is deceptive if a representation, omission or practice is likely to mislead a consumer acting reasonably, in a way that matters to their decision.

The argument runs in three steps. First, AI companies represent, explicitly and implicitly, that their systems try to produce the most accurate output they can. Second, a company that steers outputs toward other goals without saying so makes that representation misleading. Third, the reason for the steering does not matter. The FTC's press release says firms that "distort their systems' outputs to achieve undisclosed ideological objectives" could be violating Section 5.

Law firm readings of the statement agree on the third step. Spencer Fane's summary notes that profit motives, public pressure and state-law compliance are all treated the same way. Arnold & Porter quotes the statement directly: there is "no defense to deception in violation of Section 5 based on intent to comply with state law".

What the statement says is not a violation

The statement is narrower than its headline. Errors that come from genuine technical limits, such as hallucinations, do not by themselves raise Section 5 concerns. Blocking illegal content does not either, and neither do limits designed to prevent cyberattacks.

It also accepts that models balance competing goals such as brevity, clarity and relevance alongside accuracy. And it flags the reverse risk: a company that overstates how rarely its system makes mistakes could itself be making a deceptive claim. That last point matters more to most B2B vendors than anything about Colorado.

Why disclosure is the escape hatch

Every reading of the statement agrees that adequately disclosed steering avoids liability. The bar is real, though. Greenberg Traurig quotes the statement saying a one-time disclosure "subsequently hidden away in fine print" is unlikely to work. The disclosure must clearly dispel the idea that the system is designed to give the best answer possible.

The further a practice departs from what users expect, the more prominent and persistent the disclosure must be. A sentence in your terms of service will not carry it. A visible note in the product, at the point where the adjusted output appears, probably will.

What Colorado's SB 26-189 actually requires

Colorado's original AI Act, SB 24-205, was signed in 2024 and never took effect. Governor Polis signed SB 26-189 on 14 May 2026, repealing the 2024 law and replacing it with what the legislature calls the Automated Decision-Making Technology act. The 2024 law's duty of care, annual impact assessments, risk management programme and duty to notify the Attorney General of algorithmic discrimination are all gone.

The new law covers automated decision-making technology, or ADMT. That means technology that processes personal data and produces predictions, recommendations, classifications, rankings or scores used to make, guide or assist a decision about a person. A covered ADMT is one used to materially influence a consequential decision.

Consequential decisions are those affecting access to, eligibility for or compensation related to education, employment, housing, financial or lending services, insurance, health care, and essential government services. ArentFox Schiff lists exclusions for advertising, marketing, content moderation, product recommendations, scheduling and customer service triage. If your product only does those things, SB 26-189 probably does not reach it.

What developers owe

A developer builds, sells or licenses a covered ADMT. The developer's main duty is documentation for deployers. That documentation covers intended uses, categories of training data, known limitations, and instructions for appropriate use and human review. Developers must also tell deployers about material updates.

That is close to what a well-run vendor already ships as a model card or trust centre page. The difference is that it becomes a legal deliverable, and records must be kept for at least 3 years.

What deployers owe

Deployers carry the consumer-facing duties. They must give clear notice before a covered ADMT is used. After an adverse outcome, they have 30 days to give a plain-language description of the decision and the ADMT's role in it.

Consumers can request their personal data and correct factually incorrect data. After an adverse outcome they can also request meaningful human review and reconsideration, to the extent that is commercially reasonable. The Attorney General's draft rules, published on 11 August 2026, add operational detail, per Moore & Van Allen's reading of the draft. Reviewers must have genuine authority to override the decision, may not use ADMT to conduct the review, and must complete it within 45 days.

Enforcement belongs to the Attorney General alone, under the Colorado Consumer Protection Act. There is no private right of action. A 60-day cure period applies to actions started before 1 January 2030, but not to knowing or repeated violations.

Where the FTC statement and Colorado's AI law actually collide

Read the FTC press release alone and you would think Colorado orders models to lie. The release says the Colorado Act "appears to coerce companies into altering the output of their AI models to comply with and advance the state's ideological objectives". Read SB 26-189 itself and almost nothing in it touches outputs at all.

That gap is the most useful thing in this whole dispute. Our view is that the FTC is arguing with the 2024 law, and then extending the argument to the 2026 law by way of one clause.

FTC proposed statement and Colorado SB 26-189, side by side
QuestionFTC proposed policy statementColorado SB 26-189
Legal statusProposed, non-binding, comment period closed 31 July 2026.Enacted 14 May 2026, duties apply from 1 January 2027.
Who it targetsAI firms that steer outputs without disclosure.Developers and deployers of ADMT used in consequential decisions.
Core legal toolSection 5 deception.Notice, explanation, correction, human review, records.
Does it regulate outputs?Yes, it penalises undisclosed changes to them.Not directly. It regulates how decisions are explained and reviewed.
Role of disclosureClear, prominent disclosure avoids deception.Disclosure is the main obligation.
EnforcerFTC.Colorado Attorney General only, 60-day cure until 2030.

The liability allocation clause

The statement's specific objection to the revised law is liability. According to Arnold & Porter's July advisory, the FTC says the new version "poses many of the same concerns" as the original. Its reasoning is that SB 26-189 still lets developers be held liable for discriminatory outcomes caused by their customers' use of their products.

What SB 26-189 actually does here, per Moore & Van Allen, is allocate fault between developers and deployers in discrimination actions brought under existing law. It also rejects joint and several liability except where existing law allows it, and voids contract terms that indemnify a party for its own discrimination violations. Those discrimination claims come from the Colorado Anti-Discrimination Act, which exists independently of SB 26-189.

So the FTC's chain of reasoning is indirect. Liability exposure creates pressure. Pressure leads vendors to tune outputs to avoid statistically uneven results. Tuning, if undisclosed, is deception. Each link is plausible. None of them is a requirement written into the Colorado statute.

Which Colorado duties actually touch model outputs? Our assessment of SB 26-189 duties against the FTC's deception theory. Illustrative, not legal advice. SB 26-189 DUTY CHANGES OUTPUTS? FTC CONFLICT OUR CALL Developer documentationNoLowShip it Notice before useNoLowShip it 30-day adverse explanationNoLowShip it Data access and correctionInputs onlyLowShip it Human review on requestNoLowShip it 3-year record keepingNoLowShip it Discrimination fault allocationIndirect pressureMediumDisclose tuning Six of seven duties are about explaining and reviewing decisions. Only one creates pressure on outputs.
Notice where the red sits. The FTC's objection lands on a liability rule, not on any of the process duties a vendor has to build for 1 January 2027. This is our assessment, not a court finding.

The state AI laws timeline that decides your 2027

The FTC statement did not arrive alone. It is one move in a sequence that started with the executive order and includes a federal lawsuit, a Justice Department intervention and a stay of enforcement.

Ten dates, thirteen months Federal moves above the line in blue, Colorado moves below in grey. The red marker is when duties begin. 11 DecEO 14365 9 AprxAI sues 24 AprDOJ joins 27 AprEnforcementsuspended 14 MaySB 26-189 1 JulFTC proposal 31 JulComments close 11 AugAG draft rules 26 OctAG hearing 1 JanDuties begin All dates 2026 except 11 Dec 2025 and 1 Jan 2027. Sources: FTC, DOJ, Colorado General Assembly, law firm summaries.
The FTC proposal lands in the middle of a Colorado process that kept moving. The Attorney General published draft rules six weeks after the FTC spoke.

The order matters. The xAI lawsuit and the Justice Department's intervention targeted the 2024 law. The FTC statement came after Colorado had already replaced it. The Attorney General's rulemaking then went ahead as though the FTC statement did not exist, which, as a matter of law, it is entitled to do.

The stayed lawsuit nobody should ignore

xAI sued Colorado's Attorney General in federal court on 9 April 2026, in case 1:26-cv-01515 in the District of Colorado. On 24 April the Justice Department intervened, arguing that requiring AI companies to prevent unintentional disparate impact violates the Equal Protection Clause.

On 27 April the court entered an order, reported by PPC Land and Moore & Van Allen, suspending enforcement of SB 24-205 or any amending legislation until rulemaking concludes. Arnold & Porter notes the stay was not a ruling on the merits. It was granted because the law was likely to be superseded. That order is the single biggest variable for your January timeline, and we return to it below.

A policy statement is the weakest instrument an agency has. It explains how the agency intends to use powers it already holds. It does not change the law, it does not bind courts, and the FTC Act contains no express preemption clause.

The statement's preemption argument is therefore implied conflict preemption. Its own formulation, as quoted by Winston Taylor, is that such state laws are "impliedly preempted to the extent [they] conflict[] with a federal regulatory scheme." Note the hedge. To the extent they conflict. The statement never says SB 26-189 is preempted outright.

Critics have gone further. Kevin Moriarty, writing in Tech Policy Press on 23 July 2026, argued the statement "does not meaningfully argue for any implied preemption theory freeing companies from state laws regulating artificial intelligence". His sharper point is that the statement may increase the burden on AI companies, because its deception theory applies to every undisclosed adjustment, not only to those made for Colorado.

We agree with that reading, and it is the most practical insight in the whole dispute. A vendor that tunes outputs for brand safety, legal caution or a large customer's preferences, without saying so, now has a federal deception theory pointed at it. Colorado is incidental to that risk.

As of this writing, we found no final version of the statement on the FTC's site. Treat it as a live proposal that could be finalised, softened or withdrawn.

A compliance stance for AI vendors selling into Colorado

The question for a vendor is not who wins the preemption fight. It is what you can build now that holds up under every plausible outcome. Our answer is that the safe position is the same in all of them: build the Colorado process duties, and make every intentional output adjustment visible.

Start with scope. The Attorney General's draft rules offer two competing standards for when a tool materially influences a decision, per Husch Blackwell's Byte Back analysis. Under both, a tool is presumed to influence the decision unless the human decision maker reasons independently of its output. Do not assume a human in the loop takes you out of scope. The design question of where that human sits is covered in the guide to human-in-the-loop architecture.

Vendor stance by obligation, built to survive any outcome of the FTC and Colorado conflict
AreaWeak versionVersion that holds up
Scope"We are not AI, we are a scoring tool"Inventory every feature producing scores, rankings or recommendations used in the 7 consequential decision areas
Developer documentationMarketing page with capability claimsIntended uses, training data categories, known limitations and human-review instructions, versioned
Output adjustmentsFairness or safety tuning applied silentlyEach adjustment logged with its reason and disclosed in product and documentation
Accuracy claims"Unbiased", "objective", headline accuracy figuresClaims with a stated test set and date, and known failure modes listed
Deployer supportCustomer told to "handle compliance"Exports that let a deployer write a 30-day adverse-outcome explanation and run a human review
ContractsBroad indemnity for discrimination claimsFault-based allocation, since SB 26-189 voids indemnity for a party's own violations

Two rows deserve emphasis. Accuracy claims are the cheapest risk to fix and the one the FTC already enforces. Its statement cites recent cases against companies that overstated AI capabilities. The disclosure patterns that build rather than erode buyer confidence are covered in the analysis of AI disclosure and customer trust.

Output adjustments are the row where the two regimes meet. If you apply a fairness constraint, a threshold change by group, or a refusal policy, write down why, and surface it where the user sees the output. That single habit answers the FTC's deception theory and supplies the documentation Colorado requires. A logging pattern that makes it auditable is in the agent audit log specification.

If you also sell into California or the EU, the same documentation does triple duty. Compare the Colorado list against the six California AI laws that bind software vendors and the EU AI Act transparency checklist before you build three separate trust pages.

Employment is where most B2B exposure sits, because hiring and performance tools score people constantly. If your product touches workforce decisions, read where the legal line sits on AI employee monitoring alongside this piece.

Where this reading is weakest

This post argues the conflict is narrow and manageable. Here is where that argument could fail.

The stay could move the date, in either direction

The April order suspends enforcement of SB 24-205 or amending legislation until rulemaking concludes. If a court treats SB 26-189 as amending legislation, and the rules slip past January, enforcement could be on hold beyond 1 January 2027. Arnold & Porter expects the requirements to apply from that date regardless. We have not read the order itself, and on this point you need your own counsel's reading, not ours.

We read summaries of the statute, not the statute

Our description of SB 26-189 rests on the Colorado legislature's official bill summary and on law firm analyses, which disagree in small ways. The $20,000 penalty figure and the exclusion list come from ArentFox Schiff, not from statutory text we opened. The FTC statement's wording on Colorado reaches us through its press release and through law firms quoting it. A clause we have characterised as process-only could carry a broader reading.

The FTC could also finalise a much stronger statement, or move from policy to an enforcement action against a named company. One case would change the risk calculus faster than any comment period. Finally, our matrix is our judgement, and a regulator who believes fairness tuning is inherently deceptive would score the last row higher than we do.

Frequently asked questions

Does the FTC policy statement preempt Colorado's AI law?

No, not by itself. The statement is a proposal, published for comment in July 2026, and policy statements do not bind courts or create new obligations. It argues that state laws requiring deceptive output changes are impliedly preempted where they conflict with Section 5, but that theory is untested. Colorado's SB 26-189 still takes effect on 1 January 2027 unless a court or the legislature says otherwise.

When does Colorado SB 26-189 take effect?

SB 26-189 takes effect on 1 January 2027. Governor Polis signed it on 14 May 2026, and it repealed and replaced the 2024 Colorado AI Act, SB 24-205, before that law's obligations ever started. The Attorney General proposed implementing rules on 11 August 2026, with a public hearing on 26 October 2026, and those rules are also aimed at a 1 January 2027 start.

What does Colorado's new AI law require from AI vendors?

Developers of covered automated decision-making technology must give deployers documentation covering intended uses, categories of training data, known limitations and instructions for appropriate use and human review, and must flag material updates. Deployers carry the consumer-facing duties: notice before use, a plain-language explanation within 30 days of an adverse outcome, data correction, human review where commercially reasonable, and 3 years of records.

What is the FTC's Section 5 theory on AI outputs?

The FTC says AI companies implicitly represent that their systems aim for the most accurate output they can produce. Steering outputs toward undisclosed goals, including ideological goals or compliance with a state law, could make that representation misleading and therefore deceptive under Section 5. Ordinary errors from technical limits, blocking illegal content and preventing cyberattacks are not treated as violations. Clear, prominent disclosure of the adjustment is the stated way out.

Can complying with a state AI law violate federal law?

Under the FTC's proposed reading, it can, if compliance means changing outputs without telling users. The statement says intent to comply with state law is not a defence to deception. In practice, most of Colorado's duties are notices, explanations, corrections and human review, which do not change what a model outputs. The exposure sits mainly with silent adjustments made to reduce discrimination liability.

What should AI vendors do about the FTC and Colorado conflict?

Keep building Colorado compliance, because the FTC statement has not removed it. Inventory every product feature that could materially influence a consequential decision, ship the developer documentation, and make sure deployers can run notices and human review. For any output adjustment, such as a fairness constraint or threshold change, disclose it in the product and the documentation with its reason. Disclosure is the move both regulators accept.

Where to start before January

This week, list every place your product adjusts an output on purpose. Fairness constraints, refusal rules, ranking boosts, customer-specific tuning. For each one, write a single sentence stating what it does and why, then check whether a user can see that sentence anywhere near the output. Any adjustment without a visible sentence is your FTC exposure, and it exists whether or not you sell into Colorado.

Then pull the Attorney General's draft rules and map your top 3 customer use cases against the two materially-influence standards. If a customer uses your scores in hiring, lending or housing, assume you are a developer under SB 26-189 and start the documentation now. Rules can soften before January. A missing document cannot be written retroactively.

Related on state AI rules

The California picture is different in shape: six laws, mostly binding your customers. See what California's 2026 AI laws ask of software vendors.

References

  1. Federal Trade Commission, FTC seeks public comment on policy statement addressing AI accuracy, 1 July 2026. Used for the 2-0 vote, the deception framing, the Colorado language and the 31 July comment deadline.
  2. Federal Trade Commission, Proposed Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems, July 2026, published at 91 FR 41638 on 7 July 2026. The primary document. Quoted here through the press release and law firm summaries.
  3. Colorado General Assembly, SB26-189 Automated Decision-Making Technology, bill page and summary, 2026. Used for the signing date, definitions and duties.
  4. ArentFox Schiff, Colorado replaces its landmark AI Act with new framework, 22 May 2026. Used for the penalty, exclusions, cure exceptions and effective date.
  5. Arnold & Porter, Colorado narrows its AI law, but the FTC says that's not enough, 23 July 2026. Used for the FTC's view of SB 26-189 and the status of the stay.
  6. Husch Blackwell, Byte Back, Colorado Attorney General releases proposed rules for the new ADMT Act, 19 August 2026. Used for the draft rules, the two materially-influence standards and the hearing date.
  7. Moore & Van Allen, Colorado's proposed ADMT rules: what businesses need to know now, 5 October 2026. Used for review deadlines, liability allocation and the stipulated order.
  8. Kevin Moriarty, Tech Policy Press, The FTC statement on AI bias lacks conviction, 23 July 2026. Used for the critique of the preemption argument.

The weakest thing about this source base: we could not extract the text of the FTC statement or the enacted Colorado statute, so both are described through official summaries and law firm readings. Status is current as of 9 October 2026. This is analysis, not legal advice.

ST
Sidhant Tamrkar
Founding Member, Zan Digital. Writes about AI product economics, B2B software markets and what the numbers behind vendor claims actually say.

Related reading