A Cannabis Retailer’s Guide to Reducing Shrink and Inventory Variances - Get the Free Guide Now
A Cannabis Retailer’s Guide to Reducing Shrink and Inventory Variances - Get the Free Guide Now
Colorado Wrote the Cannabis Rulebook; It's Writing the AI Rulebook Next | Cannabis Business Times

Sign in or create a free Cannabis Business Times account to continue reading

Continue to Site »
Site will load in 15 seconds

Colorado Wrote the Cannabis Rulebook; It's Writing the AI Rulebook Next

Colorado wrote the cannabis licensing template that other states copied. Its new AI law is now trailblazing another regulatory path for the industry.

Frantz Ward Column Colorado Ai Template
Headshots courtesy of Frantz Ward LLP

Colorado opened the country’s first licensed adult-use dispensaries in January 2014. The licensing tiers, seed-to-sale tracking, and plant-touching compliance rules Colorado built became a template for operators everywhere, whether they were licensed in the state or not. Many states subsequently adopted regulatory concepts pioneered in Colorado, including seed-to-sale tracking and comprehensive licensing frameworks.

Colorado just did it again, this time in a different area of law that happens to sit directly on top of cannabis operations.

Cannabis Adopted AI Because It Had No Choice

Cannabis operators carry a heavier compliance load per dollar of revenue than almost any other regulated industry, and the industry has reached for AI accordingly, often to solve a problem that predates AI entirely: The underlying data was never clean to begin with.

“In this industry, the data is so scattered and is such poor quality,” says Wes Shepherd, CEO of Hoodie Analytics, one of the cannabis industry's largest analytics platforms. “The insights are there but digging them out takes an act of God.”

Hoodie now pulls data from roughly 12,000 stores a day across 14 million medical and adult-use SKUs, processing more than a billion dollars a month in retail sales data alone. Five years ago, Shepherd says, cleaning and matching that volume of data would have meant throwing a hundred analysts at the problem. Today a comparatively lean team runs it, using AI to handle the normalization work itself and freeing people for the judgment calls the software still can't make.

That's the adoption story regulators are actually reacting to. A real business problem got solved by ordinary AI tools, bought through ordinary vendor relationships, deployed by people who were focused on fixing the data mess in front of them rather than building a governance program around it.

Nobody set out to create risk. The risk showed up anyway, because that's what happens when adoption outruns oversight in any regulated industry. Colorado wrote the first rulebook for exactly that pattern in cannabis 15 years ago. It's now writing the first rulebook for the AI version of the same problem.

Why Colorado Keeps Going First

Colorado's habit of getting there first is not an accident, and it is worth understanding before assuming every state follows the same script. Colorado legalized adult-use cannabis by ballot initiative in 2012, the same election night as Washington, and then spent the next decade building the licensing and seed-to-sale infrastructure that other states later copied wholesale. That built two things beyond the cannabis program itself: a Legislature comfortable moving first on unproven regulatory territory, and an Attorney General's office with real institutional experience standing up enforcement machinery from scratch.

Colorado brought that same instinct to data in 2021 with the passage of the Colorado Privacy Act, which was one of the first five broad state privacy laws in the country. The act provides Colorado residents with control over their personal data and holds businesses accountable through compliance mandates.

The state's Legislature has now rewritten its AI statute twice in three years, first passing the sweeping Colorado AI Act in 2024, then repealing and replacing it with the Automated Decision-Making Technology Act, or ADMTA, in 2026 after two years of stakeholder pushback. That willingness to pass a law, watch it strain against reality, and rewrite it rather than simply defend it is itself part of the pattern. Other states tend to wait for a model that has already been tested. Colorado is usually the one doing the testing.

What Colorado's New Law Actually Does

In 2024, Colorado became the first state to enact what is widely regarded as the nation's first comprehensive AI statute. The Colorado AI Act (S.B. 24-205) was built around a duty of care, mandatory risk-management programs, and annual impact assessments for “high-risk” AI systems. It never took effect. After a delayed implementation date and heavy stakeholder pushback, the Legislature repealed it and started over.

Gov. Jared Polis signed Senate Bill 26-189 on May 14, 2026, repealing and reenacting Part 17 of Article 1 of Title 6 of the Colorado Revised Statutes. The replacement, now codified at Colo. Rev. Stat. §§ 6-1-1701 to -1709, is the ADMTA, which takes effect Jan. 1, 2027.

The ADMTA trades the 2024 law's risk-management bureaucracy for a leaner disclosure-and-rights model, but leaner does not mean simple. It applies when a business uses “covered automated decision-making technology” as a material factor in a “consequential decision.” A decision counts as consequential if it affects a consumer's access to, eligibility for, selection for, or compensation in employment, lending or financial services, housing, insurance, health care, education, or essential government services, or if it sets differentiated pricing or material terms that materially limit a consumer's access to any of those.

The statute sets a real threshold for what counts as “covered” technology: The tool's output must be more than a trivial input. It must be a genuine factor that constrains, ranks, scores, recommends, or classifies in a way that meaningfully shapes the outcome. Tools used solely to summarize, organize, translate, draft, route, or present information for human review are generally excluded from the definition of covered ADMT, provided they are not materially influencing a consequential decision. Ordinary advertising, marketing, and product recommendation tools are excluded outright, as are routine scheduling, customer service triage, and fraud-prevention and anti-money-laundering systems.

Most cannabis operators will sit on the deployer side of the law rather than the developer side, since they are buying and running AI tools built by someone else rather than building the tools themselves. That distinction matters because deployers carry a different set of obligations than developers, though an operator that meaningfully customizes a vendor's tool, training it on its own data or substantially changing how it functions, can end up wearing both hats.

For a deployer, the ADMTA requires three things in practice:

  • First, before using a covered tool to materially influence a consequential decision, the operator must give the consumer clear notice that the tool is or will be involved, along with instructions for getting more information. A prominent notice posted where the interaction happens, on a job application page or a financing application, for instance, satisfies this.
  • Second, if that decision produces an adverse outcome, the operator has 30 days to give the consumer a plain-language explanation of the decision and the tool's role in it, a simple way to request more detail (including the tool's name, version, and developer, and the categories of personal data used), and an explanation of the consumer's rights.
  • Third, the operator must keep records demonstrating compliance for at least three years after the decision, and every notice and disclosure has to be reasonably accessible to consumers with disabilities and limited English proficiency.

Consumers get two rights once an adverse outcome occurs: the right to correct factually inaccurate personal data used in the decision, and the right to “meaningful human review.” The statute defines that phrase narrowly enough that it will not be satisfied by a manager rubber-stamping whatever the software recommended. The reviewer has to be someone the operator has actually trained for the role, with real authority to approve, modify, or override the automated outcome, who looks at the underlying evidence rather than defaulting to the system's output, and who has enough information about the tool's limitations and principal factors to meaningfully evaluate it. Building that review process, and documenting that it happened, is likely to be the single most labor-intensive piece of compliance for most operators.

For a cannabis retailer or cultivator, the domains most likely to trigger these obligations are employment and financing. An AI-assisted hiring or background-screening tool used to evaluate budtender or cultivation applicants is squarely covered. So is an AI-driven underwriting or scoring tool used by an equipment lender, a real estate lessor, or a financing partner the operator relies on, since lending and material lease terms both sit inside the statute's covered domains.

Marketing, advertising, and ordinary loyalty-program tools will often fall outside the ADMTA because they generally do not materially influence a consequential decision. Operators should nevertheless evaluate programs that use automated scoring, purchase history, or profiling to determine eligibility for covered services or that otherwise affect access to a statutorily protected domain.

The small-business exemption did not survive. Under the original 2024 law, deployers with fewer than 50 full-time employees who did not train the AI system on their own data were exempt from most obligations. The 2026 enrolled text of S.B. 26-189 contains no employee-count exemption at all. Its only carve-outs are for HIPAA-covered entities, FDA-regulated medical devices, creditors already complying with the Equal Credit Opportunity Act, FERPA-covered education deployers, and certain insurers regulated under a separate state statute. A cannabis retailer with three employees running an AI-driven point-of-sale system is inside the ADMTA's scope in the same way as an operator with 3,000.

Enforcement runs through the Colorado Attorney General alone, under the Colorado Consumer Protection Act. There is no private right of action, and most first violations get a 60-day cure period. The AG has said enforcement will not begin in earnest until rulemaking is complete, and rulemaking is due Jan. 1, 2027, the same day the statute takes effect. Deceptive or unfair AI conduct, however, is already reachable under Colorado's existing consumer protection authority, new statute or not.

A Pattern Colorado Is Part Of, Not Ahead Of

What makes Colorado's statute worth watching is not that it is unique. Colorado confirms a pattern showing up nationally: state enforcers are not waiting for AI-specific statutes to act, and Colorado's own retreat from a heavier framework suggests other states may skip writing new laws entirely and lean on what they already have.

For example, Pennsylvania's medical licensing board sued an AI chatbot developer this spring. Commonwealth of Pennsylvania, Department of State, State Board of Medicine v. Character Technologies, Inc., No. 220 MD 2026 (Pa. Commw. Ct., filed May 1, 2026). One of the company's AI agents told a state investigator it was a licensed psychiatrist authorized to prescribe medication. The petition never invokes an AI statute. It is an unlicensed-practice-of-medicine claim under the existing Medical Practice Act, and the theory travels well: A licensing board does not need new legislation to act against an AI system operating inside a regulated profession without the credential the law requires.

Texas' Attorney General reached a comparable result from the other direction. Rather than policing what an AI system said, the state went after what a vendor claimed about its own AI. In State of Texas v. Pieces Technologies, Inc., Case No. DC-24-13476 (191st Dist. Ct., Dallas County, Tex., filed Aug. 21, 2024), the Texas AG resolved allegations that the company misrepresented the accuracy of its hospital-facing generative AI tool, including a claimed “severe hallucination rate” of less than one in 100,000, through an Assurance of Voluntary Compliance under the Texas Deceptive Trade Practices Act, Tex. Bus. & Com. Code §§ 17.41-.63. No AI statute did any work in that matter either. Ordinary consumer protection law, applied to an AI vendor's marketing, was enough.

State attorneys general have been coordinating publicly on AI as well. A bipartisan coalition of 36 state AGs wrote Congress on Nov. 25, 2025, opposing a proposed moratorium on state AI enforcement in that year's defense authorization bill. On Dec. 9, 2025, more than 40 state AGs wrote directly to major AI companies, including OpenAI, Google, Meta, and Anthropic, warning them to address “delusional” chatbot outputs or risk running afoul of state law. See Lucas Ropek, State Attorneys General Warn Microsoft, OpenAI, Google, and Other AI Giants to Fix ‘Delusional’ Outputs, TechCrunch (Dec. 10, 2025).

No single state's statute is driving that pressure. State enforcers intend to guard their authority here no matter what happens at the federal level.

Why This Lands Harder on Cannabis

Three things make this pattern more consequential for cannabis operators than for a typical retailer.

First, cannabis is a licensing-dependent industry operating inside a licensing-dependent regulatory culture. The Pennsylvania theory, that a licensing statute reaches AI conduct without needing an AI-specific law, applies with obvious force to an industry where the state licensing board already has direct authority over the business's ability to operate at all. A cannabis-specific AI tool that misrepresents its compliance capabilities sits squarely within that theory, and so does a hiring or age-verification system that a licensing regulator decides functions as an unlicensed decision-maker in a regulated process.

Second, cannabis marketing restrictions push operators toward exactly the AI-generated content and automated customer interaction that consumer protection law now treats as a default enforcement target. State advertising rules already prohibit health claims and require age-gating. An operator using AI to write product descriptions or run a chatbot under those rules picks up a second layer of exposure, since the ad must be compliant and the claims about what the AI tool does, and how accurately it does it, must also be true.

Third, cannabis retail is unusually data-heavy for its size. Loyalty programs, purchase history, delivery data, and age verification generate exactly the personal data that ADMT-style statutes are built around, and much of it is already flowing into general-purpose AI tools that nobody evaluated against what a state privacy or consumer protection regulator would call adequate governance.

Three Things to Do Now

To be compliant-ready under ADMTA’s forthcoming implementation, Colorado operators can get started on three simple steps.

  1. Inventory where automated tools already influence consequential decisions about people, including hiring, financing, lease terms, and insurance, not just seed-to-sale compliance. That is the ADMTA's actual scope, and it is broader than most operators' first instinct about what counts as “AI.”

  2. Ask every one of your AI vendors, especially marketing and compliance-tool vendors, to document what their tool does and how it performs, in writing. The Pieces Technologies matter turned entirely on a gap between marketing claims and documented reality.

  3. Build the notice-and-human-review habit before Jan. 1, 2027, forces it. A cure period only helps if you can show good-faith movement toward compliance when the AG's letter arrives at your doorstep.

Colorado did not ask cannabis operators for permission before its licensing framework became the national template. It is not asking this time either. Operators who read this one early get to build to it on their own schedule.

More in Regulations and Reform
Page 1 of 14
Next Page