I was reading Colorado's new Automated Decision-Making Technology Act and something kept making me smile. I had not written that law, obviously. But the question underneath it sounded remarkably close to the question I have been trying to answer since I began building Human Heartbeat AI: when an automated system affects a person, can the organisation show what it did, why it did it, and where a human being still has the authority to intervene?
That is not a marketing question any more. Colorado Senate Bill 26-189 takes effect on 1 January 2027. It does not make my framework mandatory, it does not turn OSCAR into a legal compliance certificate, and this note is not legal advice. What it does do is make the work behind my framework much harder to dismiss as optional.
The Rule Beneath the Rule
The Colorado law applies in defined circumstances; it is not a blanket instruction for every business everywhere. Its scope, definitions and duties matter, and any organisation affected by it should take proper legal advice. But the direction is unmistakable. For covered developers and deployers of automated decision-making technology, the statute requires records necessary to demonstrate compliance and gives people a right to meaningful human review after certain adverse consequential decisions.
Those two ideas are doing a great deal of work. Trace the decision, and keep the human review meaningful. That is not a decorative approval button at the end of a process nobody understands, nor a human being asked to rubber-stamp a confident output. It is a review with enough information, authority and reality to matter. In other words: the human owns the gate. Properly.
Why I Keep Coming Back to the Gate
If you look at what I have been building inside OSCAR, the Human Decision Gate and the separation between Runtime and Canon, this is the discipline underneath it all. AI may prepare, analyse, surface patterns, draft options and make useful work lighter. But when a consequence carries real weight, it must not quietly acquire the authority to decide what happens next.
This is not about slowing good people down for the pleasure of it. It is about keeping the moment of consequence visible: the moment someone can say yes, no, not yet, show me why, escalate this, or simply state that the decision is still theirs. A business does not lose pace by making that moment clear. It loses far more when nobody can explain who was entitled to act.
A Signal, Not a Shortcut
I know what some people will think: we are not in Colorado, so this is somebody else’s issue. Maybe, in the narrow legal sense, it is. But I would not make a business strategy out of that comfort. Colorado is a signal of a wider shift from asking whether organisations can use AI to asking whether they can evidence the way they use it. Different jurisdictions will take different routes, and UK requirements are not Colorado’s requirements. Nobody should pretend otherwise.
Still, the underlying business question travels well. Can you explain the role AI is playing in your organisation, show where the evidence came from, identify what the system was permitted to do, and let a human being intervene before a high-consequence outcome becomes real? Those are not only legal questions. They are business questions, trust questions and leadership questions.
The Businesses That Are Better Prepared
The businesses that will meet this kind of shift with the least panic are not the ones with the most policy folders. They are the ones that have already done the awkward, useful work: asked what AI is allowed to do, named what it must never do, made evidence visible, and put a person—not a vague organisational mood—at the point where authority has to be exercised.
That does not make them automatically compliant with Colorado law or any other regime. Compliance is specific, contextual and should be assessed properly. It does mean they are not beginning from zero when somebody asks the question that matters: can you prove this was done responsibly?
Where OSCAR Fits
This is where OSCAR becomes real infrastructure for me—not as a badge, a shortcut to compliance or a promise that one diagnostic makes a business legally safe. OSCAR is the place to begin asking the questions before an AI system gets embedded deeply enough to make the answers difficult to recover.
Where are the decisions that matter? Who is currently making them? What would change if AI supported that decision? What evidence would need to remain visible? Where must the human still be able to stop, challenge or authorise the next step? That is the work. It is not anti-AI; it is pro-accountability.
AI is powerful. That is exactly why it needs a proper place in the business, a visible evidence trail and a human being who still owns the consequence. That is what real governance enables: confident AI use, not reckless AI use. And if Colorado has done anything useful for the rest of us, it has made that conversation harder to avoid.
Continue through the Founder Notes series.




