Small Business Strategy
In May 2026, Colorado’s governor signed a real law about how businesses can use AI to make decisions about people. Not a proposal. Not something Congress is still arguing about. An actual, signed law with an effective date coming up in 2027. If you’ve been waiting to see whether AI regulation is even going to be a real thing, the answer for Colorado, and likely for other states following its lead, is that it already is.
And if you’re picturing this as a tech-company problem, say you run a single-location restaurant or an automotive repair shop, it’s worth slowing down for a second. If you’ve ever posted a job opening on one of the big job boards like ZipRecruiter or Indeed, there’s a real chance it used some form of AI matching or ranking on your applicants, since that’s built into how those platforms work, sometimes automatically and sometimes depending on which posting option you used. If your shop offers financing on bigger repairs, the company that approves or declines those applications may be using an algorithm to make that call. You didn’t sign up for “AI” in either case. It just came bundled with tools you were already using.
Here’s why this is actually worth your time, in plain terms. There are two different things at stake. One is legal risk: if AI is involved in a real decision about someone (hiring, firing, financing) and you skip the notice and review steps this law requires, that’s a liability problem. The other is data risk: your business’s information, or your customers’ and employees’ information, ending up inside AI tools that were never checked for what they actually do with that data afterward. Both problems come from the exact same blind spot, not knowing what AI tools are actually running in your business, and the same steps below fix both.
What the Law Actually Says
The new version is narrower and more specific than what Colorado originally tried in 2024: if a business uses AI to help make a real decision about someone (hiring, firing, a promotion), it now has to give notice that AI was involved, and if the outcome is bad for that person, explain what role the AI played within 30 days and offer a way for a human to actually review it. Here’s the twist: enforcement is currently on hold. There’s an ongoing lawsuit, and Colorado’s Attorney General has said flat out that he won’t enforce this law until a separate rulemaking process wraps up. So the obligation is real and signed. Nobody’s actually enforcing it yet (Buchalter, 2026).
What About the Federal Bill?
You may have seen headlines about a big federal AI bill in Congress. Worth being clear about what that actually is: a 269-page draft that hasn’t even been formally introduced yet, put out in June 2026 by a couple of House members. The part that got attention is a proposed freeze on new state AI laws. But here’s the detail most coverage skipped: that freeze, as written, only applies to laws about how AI models get built. It has nothing to do with laws about how a business actually uses AI day to day (Roll Call, 2026; DLA Piper, 2026).
Colorado’s law is a use law, not a build law. So even in the best case for anyone hoping Congress swoops in with one simple national standard, a law like Colorado’s keeps standing exactly as written. And Colorado isn’t the only state doing this, either. Illinois, California, New York City, and Connecticut all have their own versions of rules about AI in employment decisions, using different methods (notice requirements, bias audits, discrimination liability) but aimed at the same basic thing: how AI gets used, not how it gets built (Akin Gump, 2026). The point here isn’t to predict what Congress will or won’t do. It’s that your compliance picture doesn’t actually depend on the answer.
The Bigger Blind Spot
All of this assumes a business owner already knows what AI tools are actually being used inside their company. This is exactly where the data risk mentioned earlier comes in. A study of 2,000 employees at companies with over 500 employees, released in January 2026, found that 49% admitted to using AI tools their employer never approved. More than half of those were using free versions with no real data protections, and most didn’t see a problem with that if there wasn’t an approved option handed to them. A free tool with no data protections is, in plain terms, a tool where nobody knows what happens to the information you type into it.
Worth being straight about: that study is about big companies, not small businesses specifically. Nobody’s published the small-business version of this number yet. But it’s a fair guess that the same thing happens at smaller companies too, maybe more so. A five-person team under deadline pressure with no IT department isn’t exactly less likely to reach for whatever tool gets the job done fastest.
Here’s what that actually looks like in practice, not in the abstract: a restaurant manager pulling up a free AI tool to screen resumes between the lunch and dinner rush. A service advisor at an auto shop letting an AI-assisted estimating tool price out a repair. A financing partner’s algorithm deciding, on its own, whether to approve a customer for a repair loan before anyone at the shop even looks at it. Nobody in any of those examples set out to “bring AI into the business.” It just showed up inside tools they were already using. And in every example, both risks are live at once: a possible legal problem if the decision counts as consequential, and a data problem regardless, since information went into a tool nobody vetted.
What To Actually Do About It
Four things worth doing, regardless of what happens in Washington:
1. Walk through your own day-to-day: the job board you post to, the scheduling app you use, any financing or credit tool a customer fills out, and anything your team has started using on their own to save time. This one step covers both risks, since it’s the same list either way.
2. Flag anywhere one of those tools is quietly ranking applicants, approving or declining a customer, or influencing who gets more hours or a raise. That’s a real decision about a real person, which means it’s the legal-risk kind.
3. For anything that touches customer, employee, or business information, find out what that tool’s provider actually does with the data you send it. That’s the data-risk kind, and it’s a separate check from step two, since a tool can create a data problem without ever touching a real decision about someone.
4. Write down, in plain terms, what tool is used for what, and how someone could ask for a human to review a decision. Do this before the effective date forces you to, not after.
Bottom Line
This isn’t a maybe anymore. Colorado’s law is signed, and it’s one of several states (Illinois, California, New York City, and Connecticut among them) already regulating how AI gets used in decisions about people, even though they don’t all do it the same way. What Congress does or doesn’t do with its own bill isn’t really the deciding factor here. The actual risk isn’t that you decided to use AI. It’s tools you’re probably already using without having looked closely at what they touch and where your information goes. That’s the thing worth fixing first.
Please note: The observations and insights in this post are general in nature. The Muninn Group shares general analysis and observations in this Insights section. Specific strategic recommendations for your business require a direct engagement where your particular situation, market, competitive position, and financial reality can be assessed properly. Your first consultation is always free. The Muninn Group will not hand you a deck full of buzzwords.
Philip White is the Founder and Principal Consultant of The Muninn Group, North Carolina’s premier strategic consulting firm. He is an Economist, Political Strategist, Geopolitical Risk Analyst, and accomplished Public Speaker based in Wilmington, NC. Contact: havi@themuninngroup.com | 910-632-0431 | themuninngroup.com
Works Cited
Akin Gump. (2026, May 27). The growing patchwork of state AI laws: What it means for employers. https://www.akingump.com/en/insights/alerts/the-growing-patchwork-of-state-ai-laws-what-it-means-for-employers
Buchalter. (2026, May 19). Colorado rewrites its AI law: What employers must know about SB 26-189. https://www.buchalter.com/insights/colorado-rewrites-its-ai-law-what-employers-must-know-about-sb-26-189/
Roll Call. (2026, June 4). Bipartisan AI draft proposes three-year preemption of state laws. https://rollcall.com/2026/06/04/bipartisan-ai-draft-proposes-three-year-preemption-of-state-laws/
DLA Piper. (2026, June 5). Unpacking the Great American AI Act. https://www.dlapiper.com/en/insights/publications/2026/06/unpacking-the-great-american-ai-act
BlackFog. (2026, January 27). Shadow AI threat grows inside enterprises as BlackFog research finds 60% of employees would take risks to meet deadlines. https://www.blackfog.com/blackfog-research-shadow-ai-threat-grows/
Free Resource
How Would Your Business Score in a Consultant’s First Conversation?
Twelve questions. Five minutes. A clear, honest look at where you actually stand, no sales pitch required.
On May 14, 2026, Colorado Governor Jared Polis signed Senate Bill 26-189 into law, converting what had been characterized in public discourse as a pending regulatory possibility into an enacted legal obligation. The distinction is not semantic. SB 26-189 is not a proposal, a discussion draft, or a bill awaiting floor action. It is codified state law, carrying an effective date of January 1, 2027, that governs how businesses may deploy artificial intelligence in decisions affecting individuals, including decisions about employment. The operative question for a business owner is therefore not whether AI-specific regulation will arrive. It has already arrived.
The relevant population for this analysis is not primarily technology firms. A single-location restaurant that posts openings through a major job board is a plausible candidate for coverage, since platforms including ZipRecruiter and Indeed embed algorithmic candidate matching or ranking directly into their core hiring products, in some configurations applied by default and in others contingent on posting tier or integration. An automotive repair shop offering in-house financing on major repairs presents a comparable case, insofar as point-of-sale financing providers commonly return automated approval decisions with no human review at the point of transaction. In neither instance does the proprietor make an affirmative decision to “adopt AI.” The exposure arises from ordinary operating tools that have absorbed automated decision-making as a default feature, which is precisely the condition SB 26-189 is constructed to reach.
Two distinct categories of exposure follow from this pattern, and the remainder of this analysis is organized around them. The first is regulatory exposure: liability under a law such as Colorado’s when AI materially influences a decision about an employee or customer without the required notice, explanation, or review process. The second is information exposure: proprietary business data, customer records, and employee information passing into AI tools that were never evaluated for how that data is stored, retained, or reused downstream. Both categories share a common root cause, an owner who does not know which AI tools are actually operating inside their business, and both are addressed by the same underlying practice, developed in Section IV.
I. The Regulatory Baseline: What SB 26-189 Requires
SB 26-189 repeals and replaces Colorado’s original 2024 AI Act before that earlier framework ever took effect, and narrows its scope considerably. Where the 2024 statute imposed broad risk-management obligations on any “high-risk” AI system, the 2026 revision targets “automated decision-making technology” used in specific “consequential decisions,” including employment. Covered businesses must furnish advance notice when AI materially influences such a decision, and where that decision produces an adverse outcome, must explain the technology’s role in plain language within 30 calendar days and offer a path to meaningful human review.
Enforcement, however, does not currently track the statute’s effective date. A federal court has stayed enforcement pending resolution of an ongoing constitutional challenge, and the Colorado Attorney General has stated publicly that he will not enforce the law until the associated rulemaking process concludes. The result is a bifurcated compliance posture: the underlying legal obligation is codified and dated, while the enforcement timeline remains, at present, indeterminate (Buchalter, 2026).
II. A Multistate Pattern, Not an Isolated Statute
Colorado’s prominence in this analysis should not be read as evidence of exceptionalism. Illinois amended its Human Rights Act, effective January 1, 2026, to reach AI-mediated employment discrimination and to impose affirmative notice obligations. California’s Fair Employment and Housing Act regulations addressing automated decision systems in employment took effect October 1, 2025. New York City’s Local Law 144 has mandated bias audits for automated employment decision tools since 2023. Connecticut’s AI Responsibility and Transparency Act phases in comparable obligations for automated employment decision technology between October 2026 and October 2027 (Akin Gump, 2026).
These statutes do not converge on a single regulatory mechanism. Some rely on affirmative notice, others on discrimination liability, others on mandatory bias audits. What they share is a common target, the use of AI in decisions that affect individuals, regulated at the state level and advancing independent of any federal framework. The mechanism varies by jurisdiction. The underlying exposure does not.
III. Why Federal Preemption Does Not Alter This Analysis
A federal proposal has drawn considerable attention this year. On June 4, 2026, Representatives Jay Obernolte and Lori Trahan released a 269-page discussion draft titled the Great American AI Act. It has not been introduced as legislation and does not carry the force of law. Its most widely reported feature, a three-year preemption of state AI statutes, has in some coverage been characterized as a nationwide freeze on state regulation. The operative text is narrower: the preemption, as drafted, reaches state laws governing how AI models are built. It does not reach state laws governing how AI is used or deployed (Roll Call, 2026; DLA Piper, 2026).
This distinction is dispositive for compliance planning. Colorado’s statute, and the comparable statutes enumerated in Section II, regulate use, not development. Consequently, even under the most favorable scenario for proponents of a unified federal standard, a business relying on AI for hiring or performance decisions would remain bound by the applicable state framework. The outcome of federal legislation is not a variable that determines whether this analysis applies to a given business. It is, at most, a variable that determines whether a second, narrower layer of obligation is added on top of it.
IV. The Information Exposure Blind Spot
Each of the frameworks discussed above presumes an owner already possesses an accurate inventory of the AI tools operating within their business. That presumption warrants scrutiny, and it bears directly on information exposure, the second category identified in the introduction. A study conducted by Sapio Research on behalf of BlackFog, surveying 2,000 employees at organizations with more than 500 employees across the US and UK and released in January 2026, found that 49% admitted to using AI tools their employer had not approved. Among that group, 58% were using free-tier versions lacking enterprise-grade data governance, and 63% considered it acceptable to use AI without IT oversight when no approved tool was provided (BlackFog, 2026). A free-tier tool lacking enterprise data governance is, by construction, a tool whose data retention and reuse practices have not been evaluated by the business submitting information to it, which is the precise condition that produces information exposure.
This data describes large organizations, not small businesses specifically, and no comparable study at small-business scale currently exists. It is a reasonable inference, though not an established fact, that the underlying dynamic extends to smaller firms as well. Deadline pressure is typically more acute and formal IT oversight typically thinner in a five-person operation than in a 500-person organization, which would suggest the incentive toward unsanctioned tool adoption is not attenuated at small-business scale. No direct data confirms this inference, and it should be treated accordingly.
In practice, this exposure rarely originates in a deliberate decision to “adopt AI.” It originates in a restaurant manager using a free AI tool to screen resumes between service periods, a service advisor at an automotive shop using an AI-assisted estimating tool to price a repair, or a financing partner’s algorithm approving or declining a customer’s application before any employee reviews it. None of these instances requires the owner to have selected a vendor, executed a contract for “AI services,” or self-identified as a technology adopter. Each instance carries both categories of exposure simultaneously: a potential regulatory gap where the decision affected qualifies as consequential, and an information exposure gap in every case, since data entered a tool whose handling practices were never evaluated.
V. A Framework for Exposure Mitigation
The following four steps address both categories of exposure identified above and position a business reasonably under Colorado’s statute and the comparable frameworks enumerated in Section II:
1. Conduct a line-by-line inventory of the tools actually in use: the job board used to post openings, the scheduling software in operation, any financing or credit tool a customer interacts with, and any tool an employee has adopted independently to increase efficiency. This step surfaces both exposure categories simultaneously, since the underlying inventory is identical regardless of which category applies.
2. Identify, within that inventory, any tool that ranks job applicants, approves or declines a customer’s financing, or influences compensation or scheduling outcomes. Each such instance constitutes a consequential decision under the statutes enumerated above, and therefore a regulatory exposure point, irrespective of whether the business intended to construct an AI-mediated hiring or lending process.
3. For any tool identified in step one that processes customer, employee, or proprietary business data, determine what the tool’s provider actually does with the data submitted to it. This addresses information exposure directly and constitutes a separate inquiry from step two, since a tool can generate information exposure without ever touching a consequential decision.
4. Establish a minimal written record, identifying the tool, the decision or data category involved, and the mechanism by which an affected individual may request human review, in advance of the effective date rather than in response to it.
VI. The Bottom Line
The federal legislative debate warrants continued attention, but it is not the determinative factor in a business’s compliance posture. Colorado’s statute is enacted, and it joins an already-established, if mechanically heterogeneous, group of state frameworks, including Illinois, California, New York City, and Connecticut, that regulate how AI is used in decisions about people. The exposure identified in this analysis, regulatory and informational alike, does not originate in a business’s intent to adopt AI. It originates in tools already deployed that the business has not yet inventoried. That inventory, rather than a position on pending federal legislation, constitutes the lower-risk course of action to establish now.
Please note: The observations and insights in this post are general in nature. The Muninn Group shares general analysis and observations in this Insights section. Specific strategic recommendations for your business require a direct engagement where your particular situation, market, competitive position, and financial reality can be assessed properly. Your first consultation is always free. The Muninn Group will not hand you a deck full of buzzwords.
Philip White is the Founder and Principal Consultant of The Muninn Group, North Carolina’s premier strategic consulting firm. He is an Economist, Political Strategist, Geopolitical Risk Analyst, and accomplished Public Speaker based in Wilmington, NC. Contact: havi@themuninngroup.com | 910-632-0431 | themuninngroup.com
Works Cited
Akin Gump. (2026, May 27). The growing patchwork of state AI laws: What it means for employers. https://www.akingump.com/en/insights/alerts/the-growing-patchwork-of-state-ai-laws-what-it-means-for-employers
Buchalter. (2026, May 19). Colorado rewrites its AI law: What employers must know about SB 26-189. https://www.buchalter.com/insights/colorado-rewrites-its-ai-law-what-employers-must-know-about-sb-26-189/
Roll Call. (2026, June 4). Bipartisan AI draft proposes three-year preemption of state laws. https://rollcall.com/2026/06/04/bipartisan-ai-draft-proposes-three-year-preemption-of-state-laws/
DLA Piper. (2026, June 5). Unpacking the Great American AI Act. https://www.dlapiper.com/en/insights/publications/2026/06/unpacking-the-great-american-ai-act
BlackFog. (2026, January 27). Shadow AI threat grows inside enterprises as BlackFog research finds 60% of employees would take risks to meet deadlines. https://www.blackfog.com/blackfog-research-shadow-ai-threat-grows/
Free Resource
How Would Your Business Score in a Consultant’s First Conversation?
Twelve questions. Five minutes. A clear, honest look at where you actually stand, no sales pitch required.
