AI in Hiring: The Compliance Playbook for Automated Employment Decision Tools in 2026

AI hiring tools trigger NYC Local Law 144 bias audits, Illinois AIDA consent, EEOC disparate impact scrutiny, EU AI Act high-risk obligations, and emerging state laws. The cross-regime compliance playbook for in-house counsel.

Abstract digital fresco: dense teal crystalline forms funneling through a centered copper geometric lattice on deep navy, crossed by a single cream threshold band marking the audit point
Loading AudioNative Player...

Most companies we talk to have already deployed AI somewhere in their hiring pipeline. Resume parsing tools that rank candidates. Video interview platforms that analyze facial expressions and speech patterns. Performance scoring algorithms that feed promotion and termination decisions. The HR team bought the tool, the vendor said it was "bias-tested," and everyone moved on. What most in-house counsel do not realize is that these tools trigger a thicket of overlapping legal obligations — from NYC Local Law 144's mandatory bias audits to Illinois's AI video interview consent requirements to EEOC disparate impact enforcement to the EU AI Act's high-risk classification for employment AI systems.

The compliance gap is not theoretical. In December 2025, the New York State Office of the Comptroller issued a scathing audit of NYC's enforcement of Local Law 144, finding that the Department of Consumer and Worker Protection (DCWP) had identified only a single compliance issue among 32 companies surveyed — while the Comptroller's own review of those same companies found at least 17 instances of potential non-compliance. DCWP can impose civil penalties of $500 to $1,500 per day for each violation. Meanwhile, Colorado's AI Act (SB 24-205) took effect February 1, 2026, imposing a duty of reasonable care on deployers of high-risk AI systems to protect consumers from algorithmic discrimination — and employment decisions are squarely within its scope.

This playbook maps the legal landscape for in-house counsel: what each regime requires, which tools trigger coverage, and what you need to have in your compliance file before a regulator, plaintiff's attorney, or board member asks. We have written previously about employee AI acceptable use policies and Section 1557 AI bias audits in healthcare; this article addresses the employment-specific compliance overlay that governs AI in hiring, screening, evaluation, and termination.

NYC Local Law 144: The Enforcement Signal Everyone Missed

NYC Local Law 144, which took effect July 5, 2023, requires employers and employment agencies using "automated employment decision tools" (AEDTs) to (1) conduct an independent bias audit no more than one year before the tool's use, (2) publish a summary of the audit results on their website, and (3) notify candidates and employees that an AEDT will be used, how it will be used, and what data it collects. The law applies to any tool that "substantially assists or replaces" discretionary decision-making in hiring or promotion — covering resume screeners, video interview analysis, and algorithmic ranking systems.

The December 2025 Comptroller audit revealed that enforcement is active but uneven. DCWP received only two AEDT complaints during the two-year audit period, and its own review of 32 companies missed the vast majority of potential violations. The Comptroller found that DCWP did not use the formal enforcement procedures developed by the NYC Office of Technology and Innovation, did not consult with OTI's technical experts when evaluating suspected AEDT tools, and had not conducted additional educational outreach since the law's launch. These enforcement gaps are temporary. The audit's recommendations — implementing better complaint routing, using OTI's Enforcement Workbook, and proactively identifying non-compliance — signal that enforcement will tighten. Companies that have been flying under the radar will not stay there.

For in-house counsel, the practical requirements are straightforward but frequently unmet:

  • Retain an independent auditor. The bias audit must be conducted by an independent third party — not the vendor that built the tool. The audit should evaluate the tool's impact across sex, race/ethnicity, and intersectional categories, using historical applicant data or test data.
  • Publish the audit summary. The results must be publicly available on your website. Many companies fail this step entirely or bury the summary where candidates cannot find it.
  • Provide candidate notice. At least 10 business days before using the AEDT, you must notify candidates that the tool will be used, the categories of data it processes, and your data retention policy. This notice must appear in the job posting, the application portal, or both.
  • Refresh annually. The bias audit must be updated no more than one year before use. A tool audited in January 2025 needs a new audit by January 2026.

Penalties accrue per day, per violation — meaning a tool used for six months without a current audit can generate penalties in the tens of thousands of dollars even at the low end of the $500–$1,500 daily range.

Illinois was the first state to regulate AI-based video interviews when it passed the Artificial Intelligence Video Interview Act (AIVIA) in 2020, codified at 820 ILCS 42 (Public Act 101-0260). The law applies to employers that use AI to analyze video interviews of applicants for positions based in Illinois — meaning a company in Texas using a video interview tool on an Illinois candidate is subject to this law.

AIVIA imposes three obligations:

  • Consent. The employer must obtain the applicant's consent before using AI to analyze the video interview. Consent must be explicit and documented. If the applicant declines, the employer must use an alternative evaluation method.
  • Explanation. The employer must explain to the applicant how the AI works, including the characteristics it evaluates and how those characteristics are weighted — to the extent the employer has that information.
  • Data destruction. Within 30 days of an applicant's request, the employer must delete the video interview. This obligation extends to third-party vendors who processed the video — the employer must direct its vendor to delete the data.

The law does not create a private right of action, but violations can be enforced by the Illinois Department of Labor. More importantly, AIVIA has become the template that other states are following. Maryland passed a similar law in 2020 (HB 1202), and several states have introduced comparable consent and transparency requirements for AI in hiring.

For in-house counsel, the compliance step is simple but often skipped: if your company uses a video interview platform that employs AI analysis — tools like HireVue, Pymetrics, or similar platforms — you must build an Illinois-specific consent flow into your application process. A generic privacy policy disclosure is not sufficient. The consent must be specific to the AI analysis of the video interview, and you must maintain records of who consented and when.

EEOC Title VII and ADA: The Federal Enforcement Backbone

Regardless of which state laws apply, every employer using AI in hiring must comply with federal anti-discrimination law. The EEOC has been clear that Title VII's disparate impact framework applies to algorithmic decision-making tools with the same force it applies to traditional employment tests.

Disparate Impact Under Title VII

The EEOC's technical assistance document on Employment Tests and Selection Procedures establishes that employers cannot use neutral tests or selection procedures that disproportionately exclude persons based on race, color, religion, sex, or national origin — unless the procedure is job-related and consistent with business necessity. This framework, derived from the Supreme Court's Griggs v. Duke Power Co. decision, applies directly to AI screening tools.

If your resume parser screens out a disproportionately high percentage of female applicants, or your video interview tool produces lower scores for candidates of a particular race, you face a Title VII disparate impact claim — regardless of whether the discrimination was intentional. The EEOC has signaled in multiple enforcement actions and public statements that AI in employment is a priority enforcement area. The Commission's position is that an employer cannot deflect liability by claiming the vendor built the algorithm: the employer is responsible for the outcomes of its selection procedures, regardless of who designed the underlying technology.

ADA Accommodation Requirements for AI Tools

The EEOC has also issued guidance on the intersection of AI and the Americans with Disabilities Act. The agency's AI and ADA resource page links to the Commission's 2022 technical assistance document, "The Americans with Disabilities Act and the Use of Software, Algorithms, and Artificial Intelligence to Assess Job Applicants and Employees." The core principles:

  • Screening out. If an AI tool screens out an individual with a disability — for example, a video interview platform that penalizes atypical speech patterns or facial expressions associated with a disability — the employer must provide a reasonable accommodation unless doing so would cause undue hardship.
  • Disability-related inquiries. AI tools that ask questions or make inferences about an applicant's medical conditions may constitute prohibited "disability-related inquiries" under the ADA.
  • Vendor responsibility flows through. An employer cannot avoid ADA liability by delegating tool design to a vendor. The employer's obligation to provide reasonable accommodations exists regardless of whether the vendor built the tool with accommodation features.

For in-house counsel, this means your AI hiring vendor contracts should include representations about the tool's accessibility features, the availability of alternative evaluation pathways for candidates who need accommodations, and the vendor's obligation to cooperate with accommodation requests. For a broader framework on negotiating AI vendor terms, see our guide on AI vendor agreement clauses.

EU AI Act: High-Risk Employment Classification

If your company hires in the EU or deploys AI hiring tools that process EU candidates, the EU AI Act adds another layer. The Act, which entered into force in August 2024, classifies AI systems used in employment, worker management, and access to self-employment as "high-risk" under Annex III. This classification covers AI tools used for recruitment, selection (including advertising, screening, and evaluating candidates), and making decisions affecting terms of work — including promotion, termination, and task allocation.

High-risk classification triggers a comprehensive set of obligations for both providers (developers) and deployers (employers) of the AI system:

  • Risk management system. Deployers must implement a risk management process throughout the AI system's lifecycle, identifying and mitigating foreseeable risks.
  • Transparency and information. Deployers must inform candidates that they are subject to an AI system. In the employment context, this means candidates must be notified before the AI is used — a requirement that parallels NYC's candidate notice rule but with broader geographic reach.
  • Fundamental rights impact assessments. Under Article 27, deployers of high-risk AI systems must conduct a Fundamental Rights Impact Assessment (FRIA) before deployment, evaluating the system's potential impact on individuals' rights.
  • Human oversight. The system must be designed to allow effective human oversight. Automated decisions cannot be fully autonomous — a human reviewer must have the authority to override or modify the AI's recommendations.
  • Technical documentation and record-keeping. Deployers must maintain technical documentation, logs of system operation, and records of human review decisions.

The EU AI Act's employment provisions began applying on February 2, 2025, for prohibited practices, with high-risk system obligations applying from August 2, 2026. Companies with EU operations or EU candidates should be building compliance infrastructure now — not waiting for the enforcement window to open.

Colorado AI Act and Emerging State Laws

Colorado's AI Act, SB 24-205, signed into law on May 17, 2024, and effective February 1, 2026, is the most comprehensive state-level AI employment law enacted to date. It requires both developers and deployers of "high-risk" AI systems to use reasonable care to protect consumers from algorithmic discrimination in "consequential decisions" — a category that explicitly includes employment decisions such as hiring, firing, promotion, and compensation.

For deployers (employers), the law requires:

  • Impact assessments. Deployers must complete an impact assessment of each high-risk system, documenting the system's intended use, known risks of algorithmic discrimination, and mitigation measures.
  • Consumer notification. When a high-risk AI system is a substantial factor in a consequential decision about a consumer, the deployer must notify the consumer that the system was used, disclose the principal reasons for the decision, and provide an opportunity to appeal via human review.
  • Annual review. Deployers must annually review the deployment of each high-risk system to ensure it is not causing algorithmic discrimination.
  • Public disclosure. Deployers must publish a publicly available statement summarizing the types of high-risk systems they deploy and how they manage algorithmic discrimination risks.

The law provides an affirmative defense for entities that comply with a nationally or internationally recognized risk management framework for AI systems — such as the NIST AI Risk Management Framework. Enforcement is by the Colorado Attorney General, and violations constitute deceptive trade practices under the Colorado Consumer Protection Act.

Beyond Colorado, several states have enacted or are pursuing AI employment laws:

  • Illinois HB 3773 (Public Act 103-0804), effective January 1, 2026, amends the Illinois Human Rights Act to prohibit employers from using AI that has the effect of discriminating against employees on the basis of protected classes. It also requires employers to notify employees when AI is used in employment decisions.
  • New Jersey has introduced legislation requiring bias audits of AI hiring tools similar to NYC's model.
  • California, Massachusetts, and Vermont have all introduced bills addressing AI in employment decisions, with varying scopes and enforcement mechanisms.

Building a Cross-Regime Compliance Program

The overlapping nature of these regimes — NYC bias audits, Illinois consent, EEOC disparate impact, EU high-risk classification, Colorado impact assessments — means that compliance cannot be approached law-by-law. You need a single, unified compliance program that satisfies the most stringent applicable requirements across all jurisdictions where you hire.

Here is the framework we recommend to in-house counsel:

Step 1: Inventory Your AI Hiring Tools

List every tool in your hiring pipeline that uses AI or algorithmic decision-making. Include resume screeners, keyword matchers, video interview analysis platforms, assessment tools, chatbot screeners, and performance scoring systems. For each tool, document: the vendor, the tool's function, the data it processes, the jurisdictions where it is used, and whether it makes or substantially influences hiring decisions.

Step 2: Conduct or Obtain a Bias Audit

For each tool that qualifies as an AEDT under NYC Local Law 144 or a high-risk system under Colorado's law, obtain an independent bias audit. The audit should evaluate the tool's selection rates across race, sex, and intersectional categories, and apply the Uniform Guidelines on Employee Selection Procedures' four-fifths rule or a more rigorous statistical analysis. Document the methodology, data sources, and results.

Step 3: Build Candidate Notification Flows

Implement notice mechanisms that satisfy the most stringent applicable requirements: NYC's 10-business-day advance notice with tool description and data categories, Illinois's AI video interview consent flow, and the EU AI Act's pre-use transparency obligation. A single, comprehensive notice flow can satisfy all three regimes simultaneously.

Step 4: Establish Human Oversight Procedures

Document your human review process: who reviews AI-generated recommendations, what authority they have to override them, and what records of human review are maintained. The EU AI Act requires meaningful human oversight; the EEOC expects employers to validate AI outputs rather than blindly adopt them. Your oversight documentation is your defense against both regulatory enforcement and disparate impact litigation.

Step 5: Update Vendor Contracts

Your AI hiring vendor agreements should include: representations about bias testing and methodology, audit cooperation obligations, data deletion requirements (especially for Illinois AIVIA compliance), accommodation feature disclosures (for ADA compliance), and indemnification for discriminatory outcomes caused by the tool's design. Do not accept vendor marketing claims about "bias testing" as a substitute for contractual representations.

Step 6: Implement Ongoing Monitoring

Model performance drifts. A tool that passes a bias audit in January may produce discriminatory outcomes by July if the applicant pool shifts. Build a monitoring cadence: quarterly selection-rate reviews, annual bias audits, and immediate review when selection rates deviate from expectations. Document every review — your monitoring records are your evidence of reasonable care if a regulator or plaintiff's attorney challenges your compliance posture.

Actionable Next Steps

  1. Audit your hiring stack this quarter. Identify every tool that uses AI or algorithmic scoring in your recruitment, screening, interview, evaluation, or termination process. If you do not know whether a tool uses AI, ask the vendor — in writing. A vendor that cannot clearly explain how its tool works is a vendor that cannot help you defend a discrimination claim.
  2. Obtain independent bias audits for all AEDTs. If you have NYC candidates, you need a current audit. If you hire in Colorado, you need an impact assessment. If you hire EU candidates, you need a fundamental rights impact assessment. A single, well-structured audit can satisfy multiple regimes — but it must be conducted by an independent third party, not the vendor.
  3. Implement candidate notification flows that satisfy the strictest applicable regime. Build notice language that covers NYC's advance-notice requirement, Illinois's consent requirement, and the EU's transparency obligation. Do not build separate flows for each jurisdiction — build one comprehensive flow and apply it everywhere.
  4. Document your human oversight process. Write down who reviews AI recommendations, how they can override them, and what records are kept. If an EEOC investigator, state regulator, or plaintiff's attorney asks how your company ensures human accountability in AI-driven hiring, you need a documented answer.
  5. Update your vendor contracts. Add bias-testing representations, audit cooperation clauses, data deletion obligations, accommodation feature disclosures, and indemnification for discriminatory outcomes. If your vendor resists these terms, that tells you something about their confidence in their own product.
  6. Build a monitoring cadence and stick to it. Quarterly selection-rate reviews. Annual bias audits. Immediate investigation of any anomaly. Document everything. A compliance program that is not documented does not exist from a regulator's perspective.
  7. Align with the NIST AI Risk Management Framework. Colorado's law provides an affirmative defense for entities that comply with a recognized risk management framework. TRAIGA in Texas provides a similar safe harbor. Building your AI hiring compliance program on the NIST AI RMF gives you both regulatory protection and a defensible governance structure.
  8. Engage counsel before a complaint is filed. The cost of building a compliant AI hiring program proactively is a fraction of the cost of defending an EEOC charge, a DCWP enforcement action, or a state AG investigation — and a fraction of the reputational damage of being publicly identified as a company whose AI hiring tool discriminated. The companies that treat AI hiring compliance as a governance priority, not a legal afterthought, will be the ones that scale their hiring technology without scaling their legal risk.

Deploying AI in your hiring pipeline without a compliance framework is a liability waiting to happen. We help in-house counsel build AI hiring compliance programs that satisfy NYC Local Law 144, Illinois AIDA, EEOC guidance, the EU AI Act, and emerging state laws — in one unified framework.

Get in touch