Don’t Start With the AI. Start With the Decision │ CLICBrain Weekly Briefing – Issue #15

Compliance Intelligence for Online Businesses.

What Changed. Why It Matters. What to Do Next.

 

Don’t Start With the AI. Start With the Decision.

Operational Compliance Intelligence for Internet Businesses.

Welcome to the CLICBrain Weekly Briefing – operational compliance intelligence for internet businesses from CLIClaw.com.
Each week, we identify significant privacy, AI, advertising, data governance, email marketing, and regulatory developments and focus on what they mean operationally: what systems, workflows, governance controls, and evidence organizations should examine in response.
This week’s focus: identifying the decisions and automated workflows that may require preparation for Colorado’s revised automated decision-making framework.
On May 14, 2026, Colorado enacted SB 26-189, substantially rewriting the state’s earlier AI consumer-protection framework. The legislation repeals and reenacts those provisions with new requirements focused on automated decision-making technology, or ADMT, used to materially influence consequential decisions. The new substantive requirements apply beginning January 1, 2027.
The framework addresses specified decisions involving education, employment, residential housing, financial or lending services, insurance, healthcare services, and essential government services or public benefits. It does not treat every automated tool or every business decision as covered.
For businesses, that creates an important operational lesson. When evaluating AI and automated systems, the first question should not always be: “Is this AI?”
A better starting question may be: “What decision does this technology influence?”

 

 

 

 

 

Classify the Decision Before You Classify the Technology.

Organizations often begin AI governance with a technology inventory. That is useful. But consider two tools:
  • Tool A helps an employee rewrite an internal email.
  • Tool B scores job applicants and helps determine which candidates advance in a hiring process.
Both may use artificial intelligence. Their compliance significance can be very different.
The difference is not simply the sophistication of the technology. It is the role the technology plays in a decision about an individual.
A practical governance program therefore should not classify systems solely by labels such as:
  • Generative AI.
  • Machine learning.
  • Predictive analytics.
  • Automated decision system.
  • AI-powered tool.
It should also identify the use case, the affected individual, the decision, and the output’s influence on the result.
The guiding principle is decision-first governance: Start with what the organization decides about people, then examine the technology behind that decision.
This briefing uses Colorado’s revised law as a decision-mapping example. Whether its requirements apply depends on the organization’s role, the affected Colorado consumers, the decision context, and applicable exclusions or exemptions. Employees and job applicants can be covered consumers; the analysis is not limited to customer-facing tools.

 

 

 

 

 

Pick One Automated System That Influences a Person.

Think beyond obvious AI products. Choose one system that scores, ranks, recommends, classifies, predicts, screens, or otherwise helps your organization make a decision about an individual.
Then ask: What decision does its output influence? Does the decision concern:
  • Education enrollment or opportunity?
  • Employment?
  • Residential housing?
  • Financial or lending services?
  • Insurance?
  • Healthcare services?
  • Essential government services or public benefits?
  • Material pricing or other terms affecting access or opportunity within a covered domain?
Next, examine the technology’s actual role.
Does the system merely organize or present information without materially influencing the outcome? Or does it score, rank, recommend, classify, predict, or otherwise shape the decision, even when a person makes the final choice?
Finally, examine scope:
  • Are affected individuals covered Colorado consumers?
  • Is the organization acting as a developer, deployer, or both?
  • Does the use fall within the statutory definitions?
  • Does an exclusion or exemption apply?
  • What evidence supports the classification?
These are screening questions, not an automatic determination that a system is covered.
You may learn more from them than from asking whether the vendor calls the product “AI.”

 

Colorado Reframes the AI Governance Question.
Colorado’s SB 26-189 defines automated decision-making technology around technology that processes personal data and uses computation to generate outputs used to make, guide, or assist decisions concerning individuals. Those outputs can include predictions, recommendations, classifications, rankings, scores, and other information.
Its principal requirements concern covered ADMT used to materially influence consequential decisions. “Materially influence” is an important threshold. The automated output must be more than a trivial factor and must affect the outcome – for example, by constraining, ranking, scoring, recommending, classifying, or otherwise meaningfully altering how the decision is made. Incidental, trivial, or clerical uses do not satisfy that standard.
The consequential-decision definition also matters. It concerns specified opportunities, services, or benefits in covered domains. Certain differentiated prices, compensation, cost-sharing, or other material terms can be included when they are reasonably likely to materially limit, delay, deny, or fundamentally alter access, eligibility, or opportunity. That does not make every product recommendation, customer-prioritization rule, or automated workflow covered.
The law also contains specific exclusions, including certain fraud-prevention, cybersecurity, compliance, clerical, and information-presentation activities. Each use should be evaluated against the applicable definitions and exclusions.
The resulting governance model is: TECHNOLOGY → USE → DECISION → INFLUENCE → IMPACT → LEGAL SCOPE.
Do not stop after identifying the technology. Follow it through to the decision and the applicable requirements.

 

Why the Classification Matters.
Identifying covered ADMT is the beginning of the compliance analysis, not the end.
Colorado’s revised framework includes obligations concerning:
  • Developer documentation about intended uses, training-data categories, known limitations, and appropriate use and human review.
  • Developer communication about material updates or modifications.
  • Consumer notices.
  • Disclosures following qualifying adverse outcomes.
  • Access to and correction of personal data used in decisions.
  • Meaningful human review and reconsideration, subject to statutory conditions.
  • Compliance recordkeeping.
The framework includes post-adverse-outcome disclosures within 30 days and requires developers and deployers to retain records necessary to demonstrate compliance for at least three years.
Different obligations have different triggers. Some depend on a qualifying adverse outcome or a consumer request, rather than merely using automated technology.
Operationally, the organization needs to know:
  • Where a covered decision occurs.
  • Which technology materially influences it.
  • How an adverse outcome is identified.
  • Who provides the required notice or disclosure.
  • Who handles access, correction, and review requests.
  • What records demonstrate compliance.
A tool inventory alone may not answer those questions.

 

 

 

 

 

1. “Human in the Loop” Does Not End the Analysis. Suppose an automated tool ranks 500 job applicants. A recruiter technically makes the final decision. But the system determines which 20 applications the recruiter sees. The human’s involvement does not necessarily mean the technology falls outside the framework. The automated output may still materially influence the decision.
The better operational questions are:
  • What information does the recruiter receive?
  • Which applicants are filtered out before review?
  • How much weight does the recruiter give the score or ranking?
  • Can the recruiter depart from the output?
  • Does that happen in practice?
Also distinguish human participation in the original decision from a process for meaningful human review and reconsideration after a qualifying adverse outcome. Colorado’s revised framework addresses the latter as a consumer right, subject to statutory conditions and limitations. Ordinary participation in the initial decision should not be assumed to satisfy that separate process.
✔ CLIClaw Compliance Tip: Examine the substance of human involvement, not merely the existence of a person somewhere in the workflow.

 

2. The Vendor’s Product Description May Not Tell You Your Use Case. A vendor may describe its product as:
  • Decision support.
  • Analytics.
  • Recommendation software.
  • Workflow automation.
  • Productivity technology.
Those labels are not a substitute for examining what the technology does in your organization’s workflow.
A recommendation engine suggesting articles is different from a system ranking job applicants. A scoring tool prioritizing ordinary sales leads is different from one materially influencing access to credit. Colorado’s framework turns on statutory definitions, actual use, material influence, and applicable exclusions, not simply a product’s marketing label.
✔ CLIClaw Compliance Tip: Ask the vendor for documentation relevant to your intended use, then compare that documentation with how employees actually use the output.

 

3. Automated Decision-Making May Be Embedded in Ordinary Software. Your review should not be limited to products prominently marketed as AI. Examine scoring, ranking, recommendation, classification, and screening functions within:
  • HR and recruiting platforms.
  • Financial and lending systems.
  • Insurance platforms.
  • Tenant-screening services.
  • Healthcare systems.
  • Customer-management software.
  • Other business applications.
Inventorying a function does not mean it is covered. Colorado’s revised law includes exclusions for specified activities, including certain fraud-prevention and cybersecurity uses. It also excludes certain information-organization or presentation functions that do not produce inferences materially influencing an outcome.
The task is to identify the actual function and document why it is, or is not, within scope.

 

The Operational Problem: The Inventory Stops at the Tool.
Many AI inventories contain fields such as:
  • Tool name.
  • Vendor.
  • Department.
  • AI type.
  • Approved or not approved.
That is a useful start. But it may not describe the decision pathway or the relevant legal obligations. Consider adding:
  • USE CASE. What is the system actually being used to do?
  • DECISION. What decision does the output influence?
  • INDIVIDUAL AFFECTED. Who is affected?
  • COLORADO CONNECTION. Are affected individuals covered Colorado consumers?
  • COVERED DOMAIN. Which statutory domain, if any, does the decision concern?
  • ROLE OF AUTOMATION. Does the system make, recommend, rank, score, classify, screen, or merely organize information?
  • MATERIAL INFLUENCE. How does the output affect the outcome?
  • HUMAN PARTICIPATION. What does the original decision-maker review, and what authority do they have to depart from the output?
  • EXCLUSION OR EXEMPTION. Does one apply, and what supports that conclusion?
  • ADVERSE OUTCOME. How is a qualifying adverse result identified?
  • NOTICE AND RIGHTS WORKFLOW. Who handles disclosures, access, correction, and review requests?
  • POST-DECISION REVIEW. What process supports a qualifying request for meaningful human review and reconsideration?
  • RECORDS. What documentation is retained, where, and by whom?
These are practical governance fields, not a claim that Colorado requires this exact inventory format. The objective is to describe operational reality, not merely catalog software.

 

 

 

 

 

“The AI Doesn’t Make the Final Decision.”

Maybe not. But what does it do before the final decision?
Does it:
  • Remove candidates from consideration?
  • Rank applicants?
  • Assign a risk score?
  • Recommend approval or denial?
  • Determine which applications receive human review?
  • Establish a threshold?
  • Prioritize one individual over another?
A person may make the final selection while automated output materially shapes the available options or the result. That possibility is why Colorado’s material-influence threshold requires more than identifying who clicks the final button.
The opposite assumption is also risky: Not every automated contribution is material, and not every decision is consequential under the statute.
Document the actual influence, the covered domain, and the scope analysis.
✔ CLIClaw Compliance Tip: Do not evaluate only who makes the final decision. Evaluate how the decision gets made.

 

 

 

 

 

Trace One Automated Decision Backward.

Choose one decision your organization makes about an individual.
For example:
  • Advancing a job applicant.
  • Determining eligibility for credit.
  • Evaluating a residential rental application.
  • Setting material terms for a service within a covered domain.
Now work backward.
Ask:
  • What information influences the decision?
  • Which systems process that information?
  • Does a system score, rank, predict, classify, recommend, or screen?
  • How does the output affect the outcome?
  • What does the human decision-maker actually see?
  • Can the person depart from the output?
  • What evidence shows how that authority is exercised?
  • Are affected individuals covered Colorado consumers?
  • Does a statutory exclusion or exemption apply?
  • What happens if the result is adverse?
  • Which notice, disclosure, access, correction, or review workflows may be required?
  • What documentation supports the conclusion?
Then assign an owner for the decision pathway and any identified preparation gaps.
Do not rely only on your AI inventory. Start with a real decision, trace the technology behind it, and reconcile what you find with the inventory.
You may discover an automated use case the inventory never captured, or determine that a listed tool does not meet the law’s coverage threshold. Both findings are useful.

 

 

 

 

 

Q: Our vendor says its system is only “decision support.” Does that mean automated-decision requirements do not apply?

CLICBrain: The vendor’s label alone should not determine the analysis. Under Colorado’s revised framework, examine whether the technology meets the ADMT definition, materially influences a consequential decision concerning a covered consumer, and falls outside applicable exclusions or exemptions.
Ask:
  • What output does the system produce?
  • How is that output used?
  • Does it rank, score, classify, recommend, predict, or screen?
  • What decision does it influence?
  • Does the output affect the result, or is its role merely incidental or clerical?
  • How much weight do employees give it?
  • What human participation occurs?
  • What happens to the affected individual if the result is adverse?
  • What developer documentation supports appropriate use and review?
  • What consumer-facing processes may be required?
The same technology can play different roles depending on how an organization deploys it.
That is why governance should document the tool, the use case, the decision pathway, and the legal scope analysis.
Have another compliance question? Ask CLICBrain on CLIClaw.com.

 

Related CLIClaw Solutions.

This week’s CLICBrain Takeaway highlights two connected needs: identifying automated decision-making use cases and evaluating the risks associated with consequential decisions.
CLIClaw‘s compliance resources can help organizations evaluate related AI, privacy, data security, vendor, marketing, data governance, and operational compliance requirements and identify where risk assessments, testing procedures, incident workflows, documentation, or governance controls may need additional attention.
Explore the:
  • AI Governance & Enforcement Readiness Toolkit. Use it to establish AI inventories, use-case classifications, approval requirements, governance roles, vendor oversight, and lifecycle controls.
  • CLIClaw Compliance Library to find practical guidance, compliance programs, SOPs, checklists, assessments, FAQs, and other resources for building and maintaining an operational compliance program.

 

One Question to Take With You.

What important decision does your organization make about people that is influenced by software?
Start there. Then identify the technology, examine its influence, determine the applicable legal scope, and assign responsibility for the resulting workflows.
That may reveal more about your automated-decision risk than asking which tools have “AI” in their name.

 

CLICBrain Weekly Briefings provide operational compliance intelligence and commentary for internet businesses. Regulatory developments, enforcement activity, and legal requirements discussed herein should be evaluated in the context of your organization’s specific operations, systems, data practices, jurisdictions, and risk profile. This briefing is for informational and educational purposes only and does not constitute legal advice.