September 11, 2026
AI Ethics

AI and Employment Law: Hiring Algorithms Under New Regulation

AI and Employment Law Hiring Algorithms Under New Regulation

Hiring algorithms are now regulated by a growing patchwork of laws, not a single national rulebook. NYC Local Law 144 requires bias audits, the EU AI Act classifies most recruitment AI as high-risk, the EEOC applies existing discrimination law to algorithmic tools, and Colorado, Illinois, Texas, and California each impose their own overlapping requirements.
MythReality
A hiring algorithm built by an outside vendor is the vendor’s legal responsibility, not the employer’s.Under laws like NYC Local Law 144 and the Colorado AI Act, the deploying employer carries independent compliance obligations that cannot be contracted away, regardless of who built the tool.
Adding a human to click “approve” on an AI-ranked candidate list automatically removes the tool from high-risk regulation.Regulators including the EU AI Act’s drafters have made clear that superficial human involvement does not change a system’s risk classification unless the human genuinely exercises independent judgment on substantive, non-procedural tasks.

Why Hiring Algorithms Became a Regulatory Flashpoint

Automated employment decision tools, often shortened to AEDTs in US regulatory text, sit at the intersection of two things regulators care about most: consequential decisions about people’s livelihoods, and software that is difficult for an outside observer to inspect. A resume screener, a video-interview scoring tool, or a candidate-ranking algorithm can affect who gets an interview, who gets an offer, and who gets promoted, often without the affected person ever finding out an algorithm was involved. That combination is why hiring AI has drawn some of the most concrete, specific regulation of any AI use case anywhere in the world, well ahead of more diffuse concerns like general chatbot safety.

By mid-2026, the regulatory landscape is no longer speculative. NYC Local Law 144 has been enforced since July 2023. The EEOC issued formal guidance in 2023 applying Title VII’s disparate impact framework to algorithmic tools. The EU AI Act’s high-risk obligations for employment systems are in force. Colorado, Illinois, Texas, and California have each passed or activated their own requirements on overlapping but distinct timelines. For an HR or recruiting team deploying screening or ranking software today, the practical question is no longer “will this be regulated” but “which of five or six overlapping regimes applies to us, and which one is strictest.”

NYC Local Law 144: The Template Other Jurisdictions Borrowed

New York City’s Local Law 144 of 2021, effective since July 5, 2023, was the first law in the United States to mandate independent bias audits of AI-powered hiring and promotion tools, and it has become the reference point every subsequent law gets compared against. It applies to employers using automated employment decision tools to substantially assist or replace discretionary decision-making in hiring or promotion for positions connected to New York City.

The law has three core requirements. First, an independent bias audit must be conducted within one year before the tool is used, examining selection rates across sex, race and ethnicity, and intersectional categories. Second, a summary of the audit results must be published publicly before the tool is used. Third, candidates and employees must receive notice, at least ten business days in advance, that an automated tool will be used, along with information on what job qualifications or characteristics it assesses, and a way to request an alternative process or accommodation. The New York City Department of Consumer and Worker Protection enforces the law, with penalties ranging from 500 to 1,500 US dollars per violation, with each day of continued non-compliance treated as a separate violation.

The audit methodology itself typically leans on the EEOC’s long-standing four-fifths rule: a selection rate for any group is treated as adverse if it falls below 80 percent of the rate for the highest-scoring group. Auditors may also apply statistical significance testing instead of or alongside the four-fifths rule, particularly for tools processing large applicant pools, since the EEOC itself has cautioned that the four-fifths rule is only a rule of thumb and can miss real adverse impact when volumes are high.

How State Laws Compare in 2026

New York City’s law inspired a wave of state-level activity, but no two state laws impose identical requirements. Employers operating in more than one state now have to reconcile several different compliance regimes at once.

JurisdictionCore RequirementCompliance Trigger DateDistinctive Feature
New York City (Local Law 144)Independent bias audit, public summary, candidate noticeEnforced since July 5, 2023First mandatory bias-audit law in the US
Colorado (Colorado AI Act)Risk management policy, impact assessments, Attorney General notification of discriminationOriginal compliance duties from February 1, 2026; law repealed and reenacted via SB 26-189, new version effective January 1, 2027Deployer duty of “reasonable care,” not strict liability
Illinois (Human Rights Act amendment)Notice to applicants and employees that AI is used in employment decisionsJanuary 1, 2026Focuses on disclosure rather than mandatory audits
Texas (TRAIGA)Prohibition on AI developed or deployed with intent to discriminateJanuary 1, 2026Liability limited to intentional discrimination, with a 60-day cure period
California (Civil Rights Council regulations)Automated-decision-system rules under existing anti-discrimination lawEffective October 1, 2025Extends existing FEHA discrimination framework to cover algorithmic tools

Colorado’s Risk-Based Approach

The Colorado AI Act treats employment decisions as a “consequential decision,” which pulls hiring, promotion, and termination tools into its high-risk category. Deployers of high-risk systems must exercise reasonable care to protect people from known or reasonably foreseeable risks of algorithmic discrimination, maintain a documented risk management policy, and complete an impact assessment before deployment, annually thereafter, and within 90 days of any substantial modification. Deployers with fewer than 50 full-time employees can qualify for a narrower exemption, but only if they meet several conditions, including not training the system on their own data and relying on the developer’s own impact assessment. Notably, Colorado’s legislature revisited the law in 2026: Governor Jared Polis signed SB 26-189 on May 14, 2026, repealing and reenacting the Colorado AI Act with revised obligations that take effect January 1, 2027, so employers need to track both the original framework and its replacement.

Illinois and Texas: Disclosure Versus Intent

Illinois took a narrower, disclosure-focused path. Its amended Human Rights Act, effective January 1, 2026, requires employers to notify applicants and employees when AI will be used in recruitment, hiring, or other employment decisions, without mandating an independent audit the way New York City does. Texas’s Responsible AI Governance Act, also effective January 1, 2026, is narrower still in one sense and broader in another: it prohibits developing or deploying AI with the intent to discriminate, but liability attaches only to intentional discrimination, and the law grants a 60-day cure period before enforcement, a meaningfully lower bar than a strict liability or disparate-impact standard.

The EEOC’s Position: Existing Law Still Applies

The US Equal Employment Opportunity Commission has not asked Congress for new AI-specific legislation to bring hiring algorithms under its authority. Instead, its May 2023 technical guidance made the position explicit: Title VII’s disparate impact framework applies to algorithmic decision tools exactly as it applies to any other selection procedure. If a tool produces a substantially different selection rate for a protected group, and the employer cannot justify the tool as job-related and consistent with business necessity, the employer can be liable, regardless of whether the tool was built in-house or purchased from a vendor.

The guidance also gives employers a specific due-diligence step: ask any vendor of an algorithmic hiring tool whether the vendor evaluated the tool for adverse impact, and whether that evaluation used the four-fifths rule, a statistical significance test, or another method. Employers who skip this question and simply take a vendor’s marketing claims at face value are, in the EEOC’s framing, still on the hook if the tool turns out to discriminate.

The EU AI Act’s High-Risk Classification for Employment AI

Outside the United States, the EU AI Act takes the most structurally comprehensive approach to date. Annex III, point 4, classifies AI systems used in recruitment and selection, including targeted job advertising, application screening or filtering, candidate evaluation and ranking, and interview-response assessment, as high-risk by default. The same point of Annex III also covers AI used in promotion, termination, task allocation, and worker monitoring, making the employment category one of the broadest in the entire high-risk list.

EU AI Act ObligationWhat It Requires of Deployers
Risk management systemIdentify, evaluate, and mitigate risks the system poses across its lifecycle, not just at launch
Data governanceDemonstrate training and input data is relevant, representative, and checked for errors and bias
Technical documentation and record-keepingMaintain logs and documentation sufficient to reconstruct how a decision was reached
Transparency to affected peopleProvide instructions and disclosures so deployers and, indirectly, candidates understand the system’s function and limits
Human oversightEnsure a human can meaningfully intervene, not merely rubber-stamp an automated output

One detail catches many employers off guard: a “human in the loop” does not automatically downgrade a system’s classification. Regulatory guidance on Annex III explicitly notes that the type and degree of human involvement matters, and that a human clicking approve on an AI-generated ranking, without genuinely re-evaluating the underlying reasoning, does not change the system’s high-risk status. Deployers also carry independent obligations under the Act that cannot be shifted onto the AI vendor through a contract.

Common mistake

Many HR teams assume that keeping a recruiter “in the loop” on final decisions is sufficient, by itself, to avoid high-risk classification or audit obligations. Under both the EU AI Act and the Colorado AI Act, what matters is whether the human genuinely exercises independent judgment on substantive matters, not whether a human technically touches the workflow. A recruiter who only sees the AI’s top-ranked candidates, with no visibility into who was filtered out earlier, is not providing the kind of oversight regulators are asking for.

Practical Compliance Steps for HR and Recruiting Teams

Given the overlapping requirements, most compliance programs converge on a similar sequence of practical steps, regardless of exactly which jurisdictions apply.

  1. Inventory every tool touching a hiring, screening, ranking, or promotion decision, including tools embedded inside an applicant tracking system that HR may not think of as “AI” at all.
  2. Map each tool against the jurisdictions where affected candidates or employees are located, since obligations attach based on where the person is, not where the employer or vendor is headquartered.
  3. Request or commission an independent bias audit for any tool substantially assisting or replacing a hiring decision, using the four-fifths rule as a baseline and statistical significance testing for high-volume tools.
  4. Build a standing candidate notice process, since New York City, Illinois, and the EU AI Act all require some form of disclosure that AI is involved, even though the specific wording and timing differ.
  5. Document human oversight concretely: who reviews what, at what stage, with what authority to override the algorithm’s output, and keep records showing that override authority is actually exercised sometimes, not just theoretically available.
  6. Re-run impact assessments on a fixed schedule and after any material change to the tool, since Colorado and the EU AI Act both treat a substantial modification as a trigger for a fresh assessment.

What worked

Organizations that built one internal compliance checklist mapped to the strictest applicable requirement across all their operating jurisdictions, rather than maintaining separate jurisdiction-by-jurisdiction checklists, reported far less confusion among recruiters about which notice language or audit cadence applied to a given job posting. Treating New York City’s audit standard and the EU AI Act’s documentation standard as the effective floor, even in states with lighter requirements, reduced the risk of accidentally under-complying when a role or candidate pool crossed jurisdictional lines.

Frequently Overlooked Considerations

  • Vendor contractsA vendor’s promise that its tool is “bias-audited” does not transfer legal responsibility; deployers under most of these laws retain independent compliance obligations regardless of contract language.
  • Embedded AI featuresRanking or scoring features quietly added to an existing applicant tracking system can trigger the same obligations as a standalone hiring algorithm, even if HR never explicitly procured “an AI tool.”
  • Intersectional analysisBias audits that only check single categories, such as sex or race separately, can miss discrimination that only appears at their intersection, which New York City’s audit standard explicitly requires examining.
  • Notice timingSeveral laws require advance notice before a tool is used, not after; retrofitting notice language into an already-live job posting does not satisfy a ten-business-day requirement.
  • Cure periodsTexas’s law offers a 60-day cure period, but relying on that as a safety net across other jurisdictions is a mistake, since New York City and the EU AI Act do not offer an equivalent grace period.
  • Small employer exemptionsExemptions such as Colorado’s small-employer carve-out come with specific conditions attached; failing to meet even one condition, like using the tool beyond its developer-disclosed purpose, forfeits the exemption entirely.
  • Legislative churnLaws in this space are still being rewritten; Colorado repealed and reenacted its own AI Act within roughly two years of first passage, so compliance programs need a process for tracking amendments, not just initial statutes.

The 2026 US hiring-AI regulatory map

By mid-2026, at least five distinct US regimes are active for employment AI: New York City’s audit-and-notice model, Colorado’s risk-management model, Illinois’s disclosure model, Texas’s intent-based model, and California’s discrimination-law extension, layered underneath the EU AI Act for any employer with candidates or staff in the EU.

Glossary

Automated employment decision tool (AEDT)
A computational process, including one derived from machine learning, that substantially assists or replaces discretionary decision-making in hiring or promotion.
Bias audit
An independent evaluation of selection rates a tool produces across protected categories, used to detect disparate impact before the tool is deployed.
Four-fifths rule
An EEOC rule of thumb treating a selection rate as adverse if it falls below 80 percent of the rate for the highest-scoring group.
Disparate impact
A legal theory under which a facially neutral practice, such as an algorithmic screen, is unlawful if it disproportionately harms a protected group and cannot be justified by business necessity.
Deployer
Under EU AI Act terminology, the organization using an AI system in its own operations, as distinct from the developer that built it, carrying independent compliance duties.
Impact assessment
A documented evaluation of the risks a high-risk AI system poses to the people it affects, required before deployment and periodically thereafter under several of these laws.

Key Takeaways

  • Hiring algorithms are governed by an overlapping patchwork of city, state, national, and EU regulation rather than one unified standard.
  • NYC Local Law 144 was the first US law mandating independent bias audits and remains the reference point for later laws.
  • The EEOC applies existing Title VII disparate impact law to algorithmic hiring tools without needing new legislation.
  • Colorado, Illinois, Texas, and California each impose different obligations, ranging from risk management policies to simple disclosure requirements.
  • The EU AI Act classifies most recruitment and employment AI as high-risk by default, with obligations that cannot be contracted away to a vendor.
  • Adding a human reviewer does not automatically satisfy human-oversight requirements unless that person genuinely exercises independent judgment.
  • Employers operating across jurisdictions get better results by compliance-mapping against the strictest applicable requirement rather than managing each jurisdiction separately.

FAQs

What is NYC Local Law 144 and who does it apply to?

NYC Local Law 144 requires employers using automated employment decision tools for hiring or promotion decisions connected to New York City to conduct an independent bias audit within the prior year, publish a summary of results, and give candidates advance notice. It has been enforced by the Department of Consumer and Worker Protection since July 5, 2023.

Does the EEOC require a specific type of bias audit for hiring algorithms?

No. The EEOC’s 2023 guidance does not mandate a specific audit format, but it applies existing Title VII disparate impact rules to algorithmic tools and recommends employers ask vendors whether the four-fifths rule or a statistical significance test was used to evaluate adverse impact before deployment.

Is employment AI automatically high-risk under the EU AI Act?

Most recruitment and employment AI is classified as high-risk by default under Annex III, point 4, covering targeted job ads, application screening, candidate ranking, and interview assessment tools. This triggers obligations around risk management, data governance, documentation, transparency, and human oversight for the deploying organization.

Does having a human review AI-generated hiring recommendations satisfy oversight requirements?

Not automatically. Regulators including the EU AI Act’s guidance and the Colorado AI Act’s framework require that a human genuinely exercise independent judgment on substantive matters, not simply approve an output. A reviewer who only sees pre-filtered, AI-ranked candidates without visibility into earlier filtering steps typically does not satisfy this standard.

How does the Colorado AI Act treat employment decisions?

The Colorado AI Act classifies employment as a consequential decision area, requiring deployers of high-risk hiring or promotion AI to use reasonable care, maintain a risk management policy, and complete impact assessments before deployment, annually, and after substantial modifications. Colorado later repealed and reenacted the law via SB 26-189, with the revised version effective January 1, 2027.

What is the difference between Illinois’s and Texas’s approaches to AI hiring regulation?

Illinois’s amended Human Rights Act, effective January 1, 2026, focuses on disclosure, requiring employers to notify applicants and employees when AI is used in employment decisions. Texas’s TRAIGA, effective the same date, instead prohibits AI developed or deployed with intent to discriminate, limiting liability to intentional conduct and offering a 60-day cure period.

Can a vendor’s compliance claims protect an employer from liability?

Generally no. Under most of these laws, including NYC Local Law 144, the Colorado AI Act, and the EU AI Act, the deploying employer carries independent compliance obligations that cannot be fully transferred through a vendor contract, even if the vendor claims the tool was independently bias-audited.

What should a small HR team do first if it uses any AI screening tool?

Start by inventorying every tool that touches a hiring, screening, or ranking decision, including features embedded inside an applicant tracking system, then map each tool against the jurisdictions where affected candidates are located to identify which specific notice, audit, and documentation requirements apply.

References

  • NYC Department of Consumer and Worker Protection, Local Law 144 of 2021 guidance
  • US Equal Employment Opportunity Commission, technical guidance on AI and Title VII (May 2023)
  • Colorado General Assembly, Colorado Artificial Intelligence Act (SB 24-205) and SB 26-189
  • Illinois Human Rights Act, AI employment amendment, effective January 1, 2026
  • Texas Responsible Artificial Intelligence Governance Act (TRAIGA)
  • California Civil Rights Council, automated-decision-system regulations
  • European Union, Artificial Intelligence Act, Annex III
  • Deloitte, “NYC Local Law 144-21 and Algorithmic Bias”

For related coverage on this site, see our guide to EU AI Act compliance for a fuller walkthrough of high-risk system obligations, our comparison of AI risk management frameworks, and our tooling roundup on ML fairness auditing tooling for teams building their own bias-audit process. Readers thinking about the workforce effects of this shift may also want our pieces on managing AI job displacement and reskilling for AI and machine learning roles. For the technical side of encoding these obligations as automated checks, see our companion piece on automated compliance and policy as code.

    Avatar photo
    Laura Bradley graduated with a first- class Bachelor's degree in software engineering from the University of Southampton and holds a Master's degree in human-computer interaction from University College London. With more than 7 years of professional experience, Laura specializes in UX design, product development, and emerging technologies including virtual reality (VR) and augmented reality (AR). Starting her career as a UX designer for a top London-based tech consulting, she supervised projects aiming at creating basic user interfaces for AR applications in education and healthcare.Later on Laura entered the startup scene helping early-stage companies to refine their technology solutions and scale their user base by means of contribution to product strategy and invention teams. Driven by the junction of technology and human behavior, Laura regularly writes on how new technologies are transforming daily life, especially in areas of access and immersive experiences.Regular trade show and conference speaker, she promotes ethical technology development and user-centered design. Outside of the office Laura enjoys painting, riding through the English countryside, and experimenting with digital art and 3D modeling.

      Leave a Reply

      Your email address will not be published. Required fields are marked *