← All articles

September 11, 2026

Both Tests Look Backward

Colorado closed its first comment window on September 4 on rules that decide when an automated system materially influences a decision. Both candidate tests ask what the outcome would have been otherwise. A governor never has to ask, because it set the share before the action.

By Jonathan Luethke

On September 4, 2026 the first comment deadline passed in Colorado's rulemaking on automated decision-making technology. One of the open questions in the notice is how to tell whether an automated system materially influenced a decision, and the Attorney General put two candidate standards in front of the public and asked which to adopt.

Both of them look backward at a decision already taken. A counterfactual is not in any record.

What closed on September 4.

The Colorado Department of Law filed its Automated Decision-Making Technology and Conversational Artificial Intelligence Service rules with the Secretary of State on August 11, 2026. They implement SB 26-189, which was enacted May 14, 2026 and repealed and reenacted the state's earlier AI statute, and HB 26-1263. Comments received by September 4 are the ones the Department weighs in the revised draft it circulates no later than September 23. The full window runs to October 26, when the rulemaking hearing is held. The statute and the rules take effect January 1, 2027.

The Act reaches developers and deployers of automated decision-making technology used to materially influence a consequential decision. Consequential covers access to and terms of education, employment, housing, financial services, insurance, health care, and government benefits. Materially influence is the phrase that decides who is inside the Act, and the statute leaves the test to the rules.

So the test is being written right now, in a comment window that is half over.

Both tests look backward.

The first candidate standard puts an output outside the Act only when its effect on the outcome was trivial. The second lets it fall outside when independent information played a substantially larger role. The notice also points at evidence a regulator might read. Whether the human reviewer worked the file independently of the output. Whether outcomes tracked the reviewer's judgment rather than the system's recommendation.

Each of those asks what the decision would have been without the output. Nobody ran that decision. There is one file, one outcome, and one person who had already read the score before forming a view. A counterfactual is not an observation. It can be estimated across a population and it cannot be read off a single case, and the obligation attaches to the case.

The agreement evidence is the weaker half. A reviewer who agrees with the system almost every time may be deferring to it, or may be right almost every time about a population where the system is also right. Agreement is not deference. Disagreement is not independence. A test that reads the agreement rate measures the correlation between two readers of the same file and reports it as authority.

The quantity the rule is trying to recover.

A governor sets how much authority the next action carries, per action, at runtime, against an envelope declared before the run and outside it. The decision it makes is binary. Authority is granted or it is withheld. What a grant carries with it is a magnitude, and that magnitude is fixed before the action rather than inferred from what happened after.

That inverts the measurement problem in the notice. Colorado is asking how to recover a share from an outcome. A governor does not recover the share, because it wrote it, and what fell outside the grant never reached the actuator to influence anything. The amount of the decision the system was allowed to be is a recorded value rather than an estimate with an error bar around it.

The direction of that value is not the one a backward reading would guess. A governor can grant less authority on an action whose present trust reads higher, because its forward look caught a divergence coming before the outcome landed. Read backward from a clean outcome, that case is indistinguishable from one where the system was trusted and left alone. Read forward from the grant, it is the case where the governor pulled authority back before anything happened.

The employer who runs no system at all.

One question in the notice is concrete enough to build against. An employer operates no automated screening of its own. It retains a staffing agency, and the agency prequalifies candidates with an automated system. The notice asks whether the deployer obligations land on the employer, on the agency in something closer to a processor role, or on the agency directly as the party that issues the notices.

However that is answered, the screening runs inside the agency's system, and the decision that removes a candidate is taken there. Contracts move liability. They do not move the actuator. A control at the corporate boundary governs the paperwork that crosses it. A control before the actuator governs the screen.

The same notice concedes that developers may withhold detail as trade secret, which leaves part of a disclosure duty resting on a party the rule already expects to hold back. A runtime bound does not need that cooperation. The deploying party declares what the deployed system may do, and the governor holds realized behavior against that declaration without anyone downstream being told how the model works.

What a review count is evidence of.

The draft is precise about who may perform meaningful human review. The reviewer needs subject matter understanding proportionate to the consequence. The reviewer needs genuine authority to change the outcome. The reviewer should be independent of the original decision-maker where that is feasible, and insulated from managerial pressure. The reviewer may not lean on the automated system to do the reviewing.

Those are properties of a person and of a path. What a regulator receives is a count, produced by the system that did the routing.

That count is only as good as the vocabulary underneath it. If one outcome label covers both a restricted grant that nobody was asked about and a decision floored to a person by policy, a compliance crosswalk downstream will read the first as evidence of the second, and the report will assert oversight that nobody performed. Nothing in it is fabricated. The token meant two things and the counter picked one. Separating them, so that the handoff is reachable only from an envelope that requires a person, is what makes the count mean what the rule wants it to mean.

Once the count means that, it reads the other way around. A decision handed to a person is a decision the automated path did not finish. The honest place for that number in a run report is under deficiencies rather than under oversight.

Where the rules require nothing.

Lay the deployer duties on a timeline. Clear and conspicuous notice comes before the technology is used on a consequential decision. After an adverse outcome the deployer has thirty days. Name the decision. State what the system did and what the human did. Give the principal reasons with real specificity, and a pointer to internal standards or policy does not qualify. Disclose the inferences drawn from personal data. Tell the consumer about access, correction, and human review.

The instant between those two ends is not addressed. That instant is when the output becomes an action, and it is the only moment at which influence is set rather than described.

Colorado is not alone on the calendar. California's enrolled AI bills sit with the Governor through September 30, the employment measure among them, operative July 1, 2027 if it is signed. The NAIC released version 5.0 of what it has renamed the AI Risk Evaluation Supplement on August 31, with comments due September 29 and adoption sought at the Fall National Meeting in November. SR 26-2 has been in effect since April 17 with generative and agentic AI outside its scope, and the interagency request for information it promised has not issued nearly five months later. Each of these asks a deployer to describe its governance. None of them asks what held at the moment of the action.

What we are building.

Wayfinder Systems Group builds a runtime governor. It observes the governed system, assesses how far realized behavior has diverged from the assured trajectory, sets how much authority the next action carries, and enforces that grant at a point the system cannot step around, so an action outside the grant does not reach the actuator. The share of the decision the system was allowed to be is a value the governor wrote before the action rather than a share a reviewer reconstructs after it. The sealed record is what that grant leaves behind. We call her Velma.

Next step

Thirty minutes. Architecture, not sales.

A conversation about where the grant is set in your deployment, what the enforcement point can actually refuse, and what your human review count is evidence of.

JonathanLuethke@WayfinderSystemsGroup.com