Fractional AI Product Manager · Denver, CO
Colorado companies building AI products face constraints that most product managers have not encountered. Colorado SB205 creates documentation obligations for high-impact AI systems. Cannabis companies need AI features that comply with MED advertising restrictions. Energy companies need AI features for field operations that work in low-connectivity environments and account for safety-critical contexts.
Ibotta, Zayo Group, and Evolent Health are building AI features in Denver with these constraints. A fractional AI PM scopes the features with the regulatory requirements built into the spec from the first draft, not added after legal review flags them.
Fixed engagement, fixed scope, quoted after the discovery call. Regulatory constraints are in scope from day one.
Tell us about your Colorado AI feature requirement.
Colorado passed SB205 in 2024, making it the first state with a comprehensive AI consumer protection law effective February 2026. Companies deploying high-risk AI systems to Colorado residents in employment, financial services, healthcare, insurance, or housing must complete an annual impact assessment. The impact assessment is a product document that describes intended use, known risks, training data, and bias testing results. It is not a legal filing. The PM writes it, not the legal team.
Companies that discover SB205 applies to them after they have built the AI feature face a harder documentation problem. The intended use and training data documentation are easiest to produce before the feature is finalized. After launch, the training data vintage and the model architecture decisions may be difficult to reconstruct accurately.
Denver's regulated industries: cannabis, energy, and healthcare, add product constraints that require specific knowledge. Cannabis AI features must navigate MED advertising rules. Energy field operations tools must work in low-connectivity environments. Healthcare vendor tools must meet HIPAA requirements that go beyond standard data handling.
A fractional AI PM who has worked in these contexts writes the regulatory constraints as product requirements rather than flagging them as risks. A constraint that is a product requirement is solved by engineering. A constraint that is a risk is escalated to legal after the product is built.
MED advertising restrictions apply to any content a cannabis company distributes. An AI feature that generates content is an advertising channel, whether or not it is labeled as one.
The spec defines which output categories the AI feature cannot generate. Recommendations that would constitute advertising to under-21 audiences, claims about athletic performance, and licensed retailer references in restricted channels are prohibited outputs, not post-generation filters.
Any AI feature that generates consumer-facing content must include a classifier that flags potential MED violations before output reaches the user interface. The spec defines the classifier accuracy threshold and the review workflow for flagged outputs.
Every output filtered by the MED compliance classifier is logged with the content category, the rule triggered, and the timestamp. The audit log supports both internal compliance review and potential MED inquiry responses.
For any AI feature that generates content reaching a consumer audience, the spec documents the age verification or audience validation mechanism and the evidence that the 71.6% over-21 threshold is met for each distribution channel.
Zayo Group and Colorado's energy sector companies use AI features for field operations, routing, and network management. These are not consumer software contexts. An AI feature that routes a field technician to the wrong site or provides an incorrect equipment status has safety implications. The product spec must be written accordingly.
Safety-critical AI product specs require a hazard log: an enumeration of every scenario where an incorrect AI output could cause harm. Each hazard entry includes the scenario, the severity of harm, the probability of occurrence, and the risk control implemented. This is a design artifact, not a post-launch retrospective. It is written before engineering starts.
Field operations in Colorado frequently involve low-connectivity environments: rural network coverage gaps, underground infrastructure, and terrain that interrupts signal. An AI feature that requires continuous connectivity will fail in these conditions. The spec must define degradation modes: what the feature does at each connectivity level, how it communicates degradation to the field operator, and how it syncs when connectivity is restored.
The safe-state definition is the most important section in a safety-critical spec. It defines what the system does when it cannot produce a reliable output. The answer is always some form of human-decision mode. The spec states this explicitly, and engineering builds it as a first-class feature, not an edge case fallback.
The discovery call identifies which regulations apply to the feature before the scope is written. SB205, MED restrictions, HIPAA, and safety standards are part of the scope, not discovered mid-engagement.
Regulatory constraints are written into the spec as functional requirements. Engineering builds to them. Legal does not review the feature after it ships and flag things that were visible from the start.
Written scope and fixed price after the discovery call. The scope accounts for the regulatory complexity visible at that point. Change orders for genuinely new information, not for constraints that were knowable.
Scope your Colorado AI feature.
Describe the feature and the regulatory context you are working in. We reply within one business day.