How to Comply With Colorado’s Artificial Intelligence Act (SB24-205) When Using AI Tools in Law Firm Client Intake
Colorado’s Artificial Intelligence Act (SB24-205) requires covered “high-risk” AI systems to follow specific notice, risk management, and consumer-rights rules starting in 2026. For law firm intake, the biggest compliance issue is whether your AI tool is making or materially influencing decisions about access to legal services. This article explains how to classify intake AI, set up compliant disclosures, vendor contracts, governance, and documentation for Colorado-based clients.
Why Colorado’s AI Act matters for client intake
Client intake is no longer just a web form and a callback. Many firms now use AI chatbots to capture facts, triage practice areas, detect conflicts, score “case strength,” estimate fees, or route leads to attorneys. Those functions can improve speed and consistency—but they also create legal risk when automated outputs influence whether a person can access legal services or how they are treated during intake.
Colorado’s Artificial Intelligence Act (SB24-205) is designed to curb “algorithmic discrimination” and to require transparency and governance around certain AI uses. For attorneys, the key operational question is whether an intake tool is a “high-risk” AI system and whether your firm is acting as a “deployer” under the statute (and sometimes also as a “developer” if you build or substantially modify the tool). The compliance steps are manageable, but they require intentional design, contracting, and documentation.
SB24-205 in plain English: what it regulates
SB24-205 regulates certain AI systems that make, or are a substantial factor in making, “consequential decisions” in specified domains. While the statute has detailed definitions and exceptions, a practical framing for law firms is:
If AI outputs substantially influence whether a person gets legal representation, what services they can access, pricing/retainers, or the speed/priority of review, SB24-205 may apply.
Key concepts to map to intake workflows
High-risk AI system: An AI system used in a covered domain to make, or be a substantial factor in making, a “consequential decision.”
Consequential decision: A decision with a material legal or similarly significant effect on a consumer’s access to, cost of, or terms of important services. Intake decisions can qualify if they meaningfully affect access to legal services.
Algorithmic discrimination: Differential treatment or impact on the basis of protected characteristics (as defined under Colorado law), when caused by the AI system’s use.
Deployer: The entity using the high-risk AI system to make a consequential decision. A law firm using an intake AI tool is typically the deployer.
Developer: The entity that builds or substantially modifies the high-risk AI system. Vendors are often developers; a firm may become a developer if it materially changes model behavior (for example, training or fine-tuning with firm data to create a new decisioning model).
Is law firm intake a “covered domain” under SB24-205?
SB24-205 focuses on certain domains such as employment, housing, lending, education, insurance, and healthcare, and also addresses access to “legal services” in the context of consequential decisions in some interpretations and secondary summaries of the law’s scope. Because intake directly impacts a consumer’s access to professional services and can involve eligibility/acceptance decisions, Colorado firms should treat AI-driven intake decisioning as potentially within the statute’s “consequential decision” framework even if the tool is presented as “just triage.”
Practical takeaway: If your intake AI does more than gather information—if it recommends rejection, de-prioritization, pricing/retainer terms, or routes certain categories of consumers away from attorney review—assume SB24-205 compliance obligations are triggered and design accordingly.
A decision tree: when intake AI becomes “high-risk”
Likely not high-risk (lower SB24-205 exposure)
Purely administrative or assistive intake: AI that drafts an intake summary, extracts dates, or suggests follow-up questions, where a human makes all acceptance/decline decisions and the AI output is not used to rank or filter leads.
Content-only chatbot: A chatbot that provides general firm information (office hours, locations, scheduling) without evaluating eligibility, “case strength,” or willingness to represent.
Potentially high-risk (treat as covered unless proven otherwise)
Automated lead scoring: AI assigns a score that determines whether the lead is contacted, offered a consultation, or routed to an attorney.
Eligibility screening: AI screens out matters based on statute of limitations, damages thresholds, immigration categories, criminal history, income, or other factors, especially where screening correlates with protected classes.
Pricing/retainer recommendations: AI recommends higher retainers, different fee structures, or “premium” routing that affects cost/terms of service.
Queue prioritization: AI prioritizes which leads get human review first, if that prioritization materially affects access to representation (e.g., eviction defense, emergency injunctions).
Core compliance duties for firms using AI intake tools
SB24-205 is built around transparency, risk management, and accountability. For a law firm deployer, the compliance architecture should include (1) public-facing and individual notices, (2) a risk management program, (3) processes to detect and mitigate algorithmic discrimination, and (4) documentation and vendor oversight.
1) Provide meaningful notice when AI is used
For intake, notice is both a consumer-trust issue and a legal risk reducer. Build layered disclosures:
Website/portal notice (front-end): Disclose that AI may be used in intake communications and/or to assist in reviewing submitted information. If the AI influences routing or prioritization, say so in plain language.
Point-of-collection notice: When the chatbot or form begins gathering sensitive details (health, immigration status, criminal history, finances), disclose that the information may be processed by an AI tool and may be shared with service providers.
Adverse/negative outcome notice: If AI is used to decline or materially delay contact, add a mechanism for human review and communicate how to request it.
Example intake disclosure language (customize with counsel): “We use technology tools, including automated systems, to help route and review intake requests. An attorney reviews requests before we decide whether to offer representation. You may request a human review of any decision affecting your intake request.”
2) Offer a pathway for human review of consequential decisions
Even if your firm does not “automatically deny” matters, AI-based routing can function like a denial when it effectively prevents a person from receiving timely legal help. Create a clear escalation:
Human-in-the-loop: Require attorney or trained staff review before any “decline,” “do not contact,” or “not eligible” status is finalized.
Human-on-request: Provide an email/phone option: “If you believe this outcome is incorrect, contact us for review.” Track and resolve requests promptly.
3) Implement a risk management program tailored to intake
SB24-205 contemplates a structured approach to identify, measure, and mitigate risks of algorithmic discrimination. For firms, this should be proportional but real. At minimum:
Inventory: List every AI tool touching intake (chatbot, CRM scoring, call transcription, email triage, ad platform lead forms).
Map decisions: Document what the AI influences—routing, scoring, consultation offers, fee estimates, rejection reasons.
Identify protected-class proxies: Intake data can include proxies (ZIP code, language preference, country of origin, family status). Note where the tool might learn correlations.
Set controls: Define what the AI is not allowed to do (e.g., no race/ethnicity inference, no disability inference, no “income-based rejection” without attorney review).
4) Test for bias and disparate impact (and keep records)
Colorado’s policy goal is to reduce algorithmic discrimination. For intake, testing should focus on whether similarly situated consumers are treated differently across protected characteristics or proxies.
Practical testing methods:
Scenario testing: Submit standardized fact patterns with only non-merits variables changed (e.g., language preference, ZIP code) and compare outcomes (score/routing/consult offer).
Outcome monitoring: Track acceptance/decline rates and time-to-contact by language, geography, and referral source. Use caution when collecting sensitive demographic data; consult counsel on lawful collection and minimization.
Model change control: Re-test when prompts, vendor models, or scoring thresholds change.
Documentation: Keep a log of tests, results, mitigations, and approvals. If the Attorney General investigates, contemporaneous records are your best defense.
5) Vendor contracting: treat AI intake vendors like regulated partners
Most law firms will be deployers relying on developer-vendors. Your vendor contract and security addendum should address SB24-205 and legal ethics realities (confidentiality, supervision, data handling). Consider negotiating for:
Transparency: A description of model purpose, intended use, and known limitations. Ask whether the vendor considers the tool “high-risk” and what compliance artifacts they provide.
Testing support: The right to receive bias testing documentation or to conduct your own audits (or third-party audits) within reason.
Data limits: Clear terms on whether your intake data is used to train vendor models; many firms will require opt-out/no-training by default.
Security and incident response: Breach notification timelines, subprocessor lists, encryption, access controls.
Indemnity and allocation of responsibility: Who is responsible for what under SB24-205, especially if the vendor markets the tool for screening/decisioning.





















