Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Should You Treat AI as a Tool or a Decision-Maker?Regulations & Laws
5 min readFor Compliance Officers

Should You Treat AI as a Tool or a Decision-Maker?

Colorado's ADMT Act forces a question compliance teams have been dodging: When your AI system produces a score, recommendation, or classification, who actually made the decision?

The statute takes effect January 1, 2027, and it hinges on whether automated technology "materially influences" consequential decisions about employment, housing, credit, insurance, healthcare, education, or government benefits. The Attorney General's draft regulations, released August 11, 2026, reveal a deeper tension. Two proposed standards for "material influence" represent fundamentally different philosophies about AI's role in organizational decision-making. The one Colorado chooses will shape compliance architectures across regulated industries.

The Case for Standard #1: AI as Presumptive Decision-Maker

The first proposed standard treats AI output as materially influential unless its role was truly incidental. Under this approach, you rebut the presumption only if your human reviewer saw the primary evidence, exercised independent judgment, and reached a decision that wasn't simply consistent with what the AI recommended.

This standard reflects a view that once you introduce AI into a consequential decision workflow, you've fundamentally altered the decision architecture. Your loan officer who reviews an AI-generated credit score isn't starting from neutral. Your hiring manager who sees a resume ranked by an algorithmic screener has already been nudged. The AI output becomes the frame through which humans interpret evidence, even when they believe they're thinking independently.

Practitioners who favor this approach point to behavioral research on automation bias and anchoring effects. When your underwriter opens a file and sees "72% approval likelihood" at the top, that number shapes every judgment that follows. The standard acknowledges this reality by requiring deployers to demonstrate genuine independence, not just assert it.

From a consumer protection standpoint, Standard #1 creates clearer accountability. If your system uses AI anywhere in the decision chain for a consequential outcome, you owe the consumer transparency about that role and access to meaningful human review. You can't claim the AI was merely advisory when your decision-makers consistently follow its recommendations.

The Case for Standard #2: Preserving Human Primacy

The second proposed standard sets a higher bar for material influence. It treats AI as a non-substantial factor if your decision-maker reviewed independent information, had subject matter expertise to reach the decision without the AI, possessed authority to override the output, and actually analyzed evidence beyond what the algorithm provided.

This standard preserves a category of AI-assisted but human-driven decisions. Your insurance underwriter uses an AI tool to flag potential fraud indicators, but she reviews the full claim file, applies her professional judgment, and makes the coverage determination based on policy terms and documented evidence. Under Standard #2, that AI tool might not trigger ADMT obligations if the underwriter genuinely exercises independent authority and the AI output plays a "significantly smaller role" than her other analysis.

Compliance teams favor this approach because it maps to how they've already structured decision workflows. You've invested in training programs, implemented dual-review processes, and documented decision criteria to ensure human accountability. Standard #2 recognizes those controls as meaningful safeguards rather than treating them as window dressing.

The standard also creates breathing room for exploratory AI use. Your HR team pilots a resume screening tool but requires recruiters to review all applications and make selection decisions based on structured interviews and skills assessments. Under Standard #1, you might need full ADMT compliance from day one. Under Standard #2, you could argue the tool isn't materially influential if your recruiters demonstrably exercise independent judgment and the AI plays a minor role.

Where Practitioners Actually Land

In practice, most organizations will struggle to satisfy either standard's independence requirements for high-volume decisions.

Consider a lender processing thousands of credit applications monthly. Your underwriters review AI-generated scores, but they also see debt-to-income ratios, payment histories, and employment verification. They have authority to override the AI. They receive training on fair lending. But can you honestly claim the AI score is a "significantly smaller" factor than their independent analysis when your approval rates track the score recommendations within a few percentage points?

Or consider an employer using AI to screen resumes. Your recruiters see the ranked candidates and review resumes before scheduling interviews. They have hiring authority. But if 90% of your interviews go to candidates the AI ranked in the top quartile, did the recruiters exercise genuine independence, or did the AI materially influence who got considered?

The draft regulations acknowledge this gray area by requiring deployers to provide detailed post-adverse-outcome disclosures describing "the respective roles of the ADMT and any human reviewers." That language assumes both played a role. The disclosure must explain principal reasons with "real specificity" and describe whether those reasons consisted of AI-generated inferences, profiles, or scores.

Those disclosure requirements effectively presume material influence in most real-world scenarios. If you're using AI to process personal data and generate output about individuals in consequential domains, you're likely a deployer under either standard.

Our Take

Standard #2 is more defensible legally but harder to prove operationally.

The independence factors (reviewed other information, subject matter expertise, genuine authority, AI played smaller role) create a workable test for whether AI truly assists rather than drives decisions. But documenting that your decision-makers consistently satisfy all five factors requires evidence most organizations don't collect today.

You'll need decision logs showing what information reviewers accessed beyond AI output. Training records demonstrating subject matter competency. Approval/override rates proving reviewers exercise independent judgment. Workflow documentation establishing that reviewers analyze primary evidence, not just AI summaries.

If you're building that evidence infrastructure anyway to demonstrate meaningful human review, you're already treating your AI system as covered ADMT. The practical compliance burden doesn't change much between standards.

The real question isn't which standard Colorado adopts. It's whether your organization is prepared to defend the role AI plays in your consequential decisions with specific evidence rather than general assertions about human judgment.

Start by mapping where AI touches consequential decisions in your workflows. Document what information your decision-makers see, what training they receive, and what authority they exercise. Track override rates and decision patterns. Build the evidence foundation now, before the January 1, 2027 effective date forces you to construct post-adverse-outcome disclosures you can't actually support.

The Attorney General is accepting written comments through October 26, 2026. But regardless of which standard becomes final, the core statutory obligations for notice, disclosure, and consumer rights take effect on schedule. Don't wait for regulatory clarity to begin compliance planning.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like