Direct comparison
SB 53 vs Colorado AI Act vs NY RAISE Act
SB 53, the Colorado AI Act, and NY's RAISE Act compared: what each regulates, coverage triggers, requirements, penalties, and effective dates.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about SB 53 vs Colorado AI Act vs NY RAISE Act
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do California SB 53, Colorado AI Act, New York RAISE Act compare side by side?
The table below compares California SB 53, Colorado AI Act, New York RAISE Act across 5 procurement-relevant dimensions, from what type of ai system it regulates through effective dates.
Side-by-side comparison
| Dimension | California SB 53 | Colorado AI Act | New York RAISE Act |
|---|---|---|---|
| What type of AI system it regulates | Frontier models: foundation models trained using more than 10^26 integer or floating-point operations of compute. Coverage is defined by the model itself, not by any particular use case it is put to. | "Automated decision-making technology" (ADMT) that materially influences a "consequential decision" about a person — access to, eligibility for, or compensation related to education, employment, housing, financial or lending services, insurance, health care, or essential government services and public benefits. No compute or model-size threshold; an ordinary scoring or classification tool is covered if it is used this way, and a frontier model is not covered unless it is used this way. | Frontier models: models trained using more than 10^26 computational operations and more than $100 million in aggregate training compute cost, plus models built by knowledge-distilling a frontier model where the distillation itself costs more than $5 million. Like SB 53, coverage is defined by the model, not its use. |
| What triggers coverage | Training, or beginning to train, a model past the 10^26-operation compute threshold makes an entity a "frontier developer," owing a baseline transparency report. The heavier duties — a public Frontier AI Framework, catastrophic-risk detail in transparency reports — apply only to "large frontier developers": frontier developers whose annual revenue, with affiliates, exceeded $500 million in the prior calendar year. | Developing or deploying covered ADMT that materially influences a consequential decision about a Colorado resident, regardless of company revenue or the model's compute. "Developers" build or substantially modify the technology; "deployers" put it to use. Some entities are exempted to the extent they already comply with equivalent obligations under other law. | Crossing the compute-and-cost threshold as a "large developer": having trained at least one frontier model and spent more than $100 million in aggregate compute cost training frontier models. Academic research institutions are exempt. |
| What the law requires | Large frontier developers must publish and annually review a Frontier AI Framework describing how they identify and manage catastrophic risk. All frontier developers must publish a transparency report before deploying a new or substantially modified model; large developers' reports must also cover catastrophic-risk assessment results and third-party evaluator involvement. Developers must report critical safety incidents to the state Office of Emergency Services, and large developers must run an anonymous internal whistleblower channel (Labor Code section 1107.1 also bars retaliation against anyone who discloses catastrophic risk to authorities). | Developers (effective Jan. 1, 2027) must produce technical documentation — intended use, training-data categories, known limitations, human-review instructions — and notify deployers of material updates. Deployers must give consumers clear notice at the point of interaction with a covered ADMT, provide a plain-language explanation of the system's role within 30 days of an adverse decision, let consumers correct inaccurate personal data, and offer meaningful human review of adverse outcomes on request. Both must keep compliance records for at least three years. | Before deployment, large developers must adopt written safety and security protocols covering critical-harm mitigation, cybersecurity, and testing methodology; publish a redacted version and submit it to the state Attorney General and the Division of Homeland Security and Emergency Services; retain unredacted records for as long as the model is deployed plus five years; and report safety incidents within 72 hours. A model cannot be deployed if it poses an unreasonable risk of critical harm. |
| Enforcement and penalties | California Attorney General only, through civil actions; no private right of action. Civil penalties up to $1,000,000 per violation, scaled to severity. | Colorado Attorney General only; violations are treated as a deceptive trade practice under the state Consumer Protection Act. Through January 1, 2030, the AG must give 60 days' notice and a chance to cure before pursuing enforcement. The law creates no new private right of action, though it sets rules for allocating fault between developers and deployers in existing discrimination lawsuits. | New York Attorney General only, through civil actions; no private right of action. Civil penalties up to $10,000,000 for a first violation and up to $30,000,000 for subsequent violations, plus injunctive or declaratory relief. |
| Effective dates | Signed September 29, 2025. Core obligations took effect January 1, 2026 — already in force. | The original Colorado AI Act (SB24-205) was signed May 17, 2024, with an effective date of February 1, 2026 that was first delayed to June 30, 2026 by Senate Bill 4 (signed August 28, 2025). Before that date arrived, the law was repealed and reenacted by SB26-189, signed May 14, 2026 (Chapter 131), which carries the consequential-decision concept forward as an automated-decision-making-technology framework. Its developer documentation duties, and the Attorney General's implementing rules, are due January 1, 2027. | Signed December 19, 2025 (Chapter 699). The act took effect 90 days after becoming law, around March 19, 2026 — already in force. |
Common questions
Common questions about California SB 53 vs Colorado AI Act vs New York RAISE Act
Do these three laws regulate the same kind of AI system?
+
No. California SB 53 and New York's RAISE Act both regulate frontier models directly, defined by a compute threshold, regardless of what the model is used for. Colorado's law regulates by use case: it covers any automated decision-making technology, however small, when it materially influences a consequential decision like employment, housing, or credit.
Is the original Colorado AI Act (SB24-205) still the law?
+
Not as such. It was repealed and reenacted by SB26-189, signed May 14, 2026, before its delayed June 30, 2026 enforcement date ever arrived. The new automated-decision-making-technology framework keeps the same consequential-decision concept, with developer-facing duties phased in starting January 1, 2027.
Which of these laws are already in force?
+
California SB 53 (since January 1, 2026) and New York's RAISE Act (since roughly March 19, 2026) are both already in force. Colorado's reenacted framework is law as of May 14, 2026, but its main developer documentation duties do not begin until January 1, 2027.
Could one company be covered by all three?
+
Yes. A frontier developer that meets SB 53's and the RAISE Act's compute-and-size thresholds and whose model is also used to help make consequential decisions — screening job applicants or loan applications, for example — for Colorado residents can owe duties under all three laws at once, on three different definitions of what triggers coverage.







