Comment on Colorado ADMT Proposed Rules: Training Data Certification
Box Commons · 30 N Gould St Ste N, Sheridan WY 82801
- SB 26-189 creates training data documentation requirements but no verification mechanism — disclosure without audit is unverifiable attestation.
- Independent data certification resolves the verification asymmetry through a three-layer architecture with a public registry.
- Live proof of concept: BC-Certified audio data pipeline operating across 22 radio stations demonstrates training data transparency is technically feasible today.
+ Jump to Section
I. Executive Summary
Box Commons recommends that the proposed rules implementing the Automated Decision-Making Technology Act (SB 26-189) and the Chatbot Safety Act (HB 26-1263) recognize independent, third-party data certification as a structured mechanism by which developers can satisfy their training data documentation obligations and deployers can satisfy their vendor oversight duties.
Specifically, we recommend that the final rules establish a rebuttable presumption that a developer's use of datasets certified by an independent standards body — one meeting defined governance criteria — constitutes adequate documentation of "the categories of data, including personal data, used to train the Covered ADMT" as required by the Act.
This comment draws on our experience operating a live audio data certification pipeline across a 22-station broadcast radio network, demonstrating that the training data transparency SB 26-189 contemplates is technically feasible, operationally affordable, and independently verifiable today.
II. The Training Data Documentation Gap
SB 26-189 requires developers to provide documentation including "the categories of data, including personal data, used to train the Covered ADMT." However, neither the statute nor the proposed rules address how the deployer — or the Attorney General — can verify that the documentation is accurate.
The Verification Asymmetry: Developers know what data they used. Deployers and regulators do not. Disclosure without verification is attestation — the developer's word, unaudited. The insurance industry has already encountered this asymmetry. When ISO released CG 40 47 and CG 40 48 in January 2026, the exclusions exposed a consent verification gap that attestation alone could not resolve. Gallagher Re documented a 978.1% increase in generative AI-related lawsuits from 2021 to 2025. Emerging AI coverage providers — Armilla, Munich Re aiSure, Testudo — now require data provenance audits as a condition of coverage because self-attestation proved insufficient.
III. How Independent Data Certification Works
Independent data certification interposes a trusted intermediary between the data producer, the ADMT developer, and the regulator through a three-layer architecture:
Standards Body: Publishes technology-agnostic certification standards, accredits third-party certifiers, maintains a public registry of certified datasets.
Accredited Certifiers: Conduct independent audits of datasets against published standards, issue certifications with defined scope and validity.
Certified Data Producers: Submit datasets for audit; receive certification marks that travel with the data through the supply chain.
Under this architecture, the ADMT developer incorporates certified datasets and documents the certification scope. The deployer relies on the certification for vendor oversight. The Attorney General verifies compliance by checking a public registry — no inspection of proprietary models required.
IV. Proof of Concept: Audio Data Certification in Operation
BC-Certified covers audio data across a 22-station broadcast radio network operated by Audilous Media. The certification pipeline verifies consent chains (broadcaster retains original broadcast rights), content separation (human-created vs. AI-generated audio), metadata completeness (artist, title, timestamp, ISRC where available), and format integrity (uncompressed or lossless source files).
This is a live operational system, not a whitepaper. Audio data is flowing through the pipeline today. The 22-station proof demonstrates that training data transparency is technically feasible, not theoretical, and that independent certification can operate at broadcast scale without disrupting station operations.
Audio matters for ADMT because voice cloning, synthetic speech, and audio deepfakes are among the highest-impact AI harms currently facing consumers. Colorado's ADMT rules will govern AI systems that process audio data — systems whose training data provenance has immediate implications for consumer protection.
V. The HITRUST Precedent
The HITRUST CSF certification provides the most direct precedent for what we propose. HITRUST resolved the same information asymmetry in healthcare: covered entities needed to verify the security practices of business associates who would not disclose proprietary security architectures. The solution was a trusted intermediary — the certifier — who evaluates the vendor under NDA and issues a credential the covered entity can rely upon.
Replace "cybersecurity" with "training data provenance," replace "business associate" with "AI developer," and the compliance pattern transfers intact to Colorado's ADMT framework.
Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]
Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.
Related Analysis
What No One Is Saying About Colorado's ADMT Rules
StandardsThe Verification Gap: Why AI Training Data Documentation Needs Independent Certification
Risk & InsuranceAudio Data Is the Next AI Liability Frontier
Risk & InsuranceWhat ISO CG 40 47 and CG 40 48 Mean for AI Companies
StandardsHITRUST for AI Training Data: Why the Healthcare Precedent Matters
Related Filings
Comment on NAIC BDAI Working Group: Exhibit B/D Mapping
Proposes a 'Presumption of Conformity' framework within the NAIC AI Systems Evaluation Tool permitting insurers to satisfy third-party vendor oversight obligations under Exhibits B and D through valid certifications from independent AI credentialing bodies, following the HITRUST precedent.
CPPAPreliminary Comment on CPPA Opt-Out Preference Signals
Addresses AB 566, AI systems processing opt-out signals, the verification gap, and independent third-party credentialing as a scalable compliance pathway for California's expanding privacy framework.
NHTSAComment on NHTSA Zoox FMVSS Exemption Petition
Does not oppose Zoox's petition but proposes a four-element conformance pattern (published criteria, independent assessment, machine-readable attestation, continuous reporting) that NHTSA could condition any temporary FMVSS exemption upon, mapping to existing conformity assessment architectures.