AI-specific hiring rules — bias audits, candidate notices, consent for video analysis — are narrow, patchy and lightly enforced. The discrimination statutes underneath them are broad, apply everywhere, and are enforced by private plaintiffs with damages at stake. Most compliance effort goes into the first layer and most liability sits in the second.
Information, not legal advice. Reviewed 4 August 2026. The AI-specific rules cited here have effective dates that have already moved once in at least two jurisdictions, and the federal enforcement posture in the United States changed materially in 2025 without any change to the underlying statutes. Verify effective dates and check whether guidance you rely on is still published.
The frame: two layers, and one does the work
Layer one is AI-specific: bias audit obligations, disclosure requirements, consent rules for particular technologies. These are procedural. They tell you to test, to publish and to notify. Almost none of them tells you what result is unlawful.
Layer two is discrimination law: Title VII, the ADEA and the ADA in the US, the Equality Act 2010 in the UK, national implementations of the EU equal treatment directives. These are substantive. They make a discriminatory outcome unlawful regardless of how it was produced, they have been enforced for decades, and they carry damages.
The gap between them is where the risk lives. You can complete a bias audit, publish the summary, send every notice on time, and still be liable under Title VII because the tool produced a disparate impact you could not justify. Compliance with the AI-specific rule is not a defence to the discrimination claim.
New York City Local Law 144
Enforced since July 2023, this is the most-cited AI hiring rule in the world and it is a municipal ordinance. It applies to an “automated employment decision tool” used to substantially assist or replace discretionary decision-making for hiring or promotion for a position in New York City.
| Obligation | Description |
|---|---|
| Bias audit | An independent impartial evaluation, conducted no more than one year before use, calculating selection or scoring rates by sex category and by race/ethnicity category and by the intersection of the two, and impact ratios comparing each to the most-selected category. |
| Publication | A summary of the most recent audit results published on the employer's or agency's website, including the date of the audit and the distribution date of the tool, and the source and explanation of the data used. |
| Candidate notice | At least ten business days before use, notice to candidates and employees who reside in the city that the tool will be used, the job qualifications and characteristics it will assess, and the source and retention policy of the data collected — the last on request. |
| Enforcement | By the Department of Consumer and Worker Protection. Civil penalties of several hundred dollars for a first violation and up to the low thousands for subsequent ones, with each day of non-compliance and each failure to notify counting separately. No private right of action. |
Two limits are worth knowing. The audit measures selection rates by demographic category; it does not assess whether the tool is valid, whether the characteristics it scores are job-related, or whether a less discriminatory alternative exists — all of which are the questions Title VII asks. And enforcement has been thin: independent researchers surveying covered employers in 2024 found published audit summaries for only a small fraction of the employers apparently within scope, with the “substantially assist” threshold and the city-residence limitation both used to argue the law does not apply.
Illinois: three separate statutes
Illinois has the densest stack, and the AI-specific pieces are the least dangerous of the three.
- The Artificial Intelligence Video Interview Act, in force since 2020, applies to employers who use AI to analyse video interviews for positions based in Illinois. Before the interview: notify the applicant that AI may be used, explain how it works and what general types of characteristics it uses to evaluate, and obtain consent. Afterwards: share the video only with those whose expertise is necessary, and destroy it and all copies within 30 days of an applicant’s request. Employers who rely solely on AI analysis to decide who advances to an in-person interview must report demographic data to the state.
- HB 3773, effective 1 January 2026, amends the Illinois Human Rights Act. It is a civil rights violation to use AI with respect to recruitment, hiring, promotion, discipline, discharge or other terms of employment where the AI has the effect of discriminating on a protected class, or to use ZIP code as a proxy for a protected class. Notice is required when AI is used for those purposes. Because it sits inside the Human Rights Act, it comes with that Act’s enforcement machinery rather than a bespoke one.
- The Biometric Information Privacy Act is not about AI and is the one that generates litigation. Collecting a biometric identifier — a face geometry scan or a voiceprint, which video and voice analysis tools may produce — without a written release and a published retention schedule is actionable by the individual, with statutory damages per violation. Class actions under it have produced very large settlements.
Colorado, Maryland and the rest
Colorado. Employment is a “consequential decision” under the Colorado AI Act, so a hiring tool is a high-risk system and both the developer and the deployer carry duties: impact assessments, a risk management programme, notice before use, and on an adverse decision a statement of the principal reasons, an opportunity to correct data and a right to appeal for human review. The effective date has moved once already, from February 2026 to mid-2026; check the current one.
Maryland has required an applicant’s signed consent before using facial recognition during an interview since 2020. Short statute, narrow scope, easy to miss.
California regulations on automated decisionmaking reach employment and independent contracting opportunities, and the state’s civil rights regulations were updated to address automated decision systems in employment. Several other states have introduced hiring-specific bills; most have not passed.
The EU: high-risk by default
Under the AI Act, Annex III area 4 covers employment and worker management: systems for recruitment or selection, including targeted job advertisements, analysing and filtering applications and evaluating candidates; and systems for decisions on promotion or termination, task allocation based on behaviour or personal traits, and monitoring and evaluating performance. A CV-screening tool is high-risk without argument.
That brings the full stack: for the provider, Articles 8 to 15 and a conformity assessment; for the deployer, Article 26, including human oversight by a competent person, monitoring, log retention, and the duty to inform workers’ representatives and affected workers before putting the system into service. If you built the tool yourself on a general model, you are both.
On top of that sits GDPR Article 22 on solely automated decisions and, for platform work specifically, the Platform Work Directive (EU) 2024/2831, whose algorithmic management chapter restricts processing of certain personal data by digital labour platforms, requires human review of significant automated decisions and transparency about monitoring systems. Member States were given two years to transpose it, so the national rules are what will actually bind and they arrive at the end of 2026.
The discrimination law underneath
In the US, the analysis that decides cases is unchanged since Griggs v. Duke Power (1971). If a selection procedure produces a disparate impact on a protected group, the employer must show it is job-related and consistent with business necessity; even then, the plaintiff may prevail by showing a less discriminatory alternative that serves the employer’s interest. The Uniform Guidelines on Employee Selection Procedures, at 29 CFR Part 1607, are the long-standing framework, and their four-fifths rule — a selection rate for any group less than four-fifths of the highest group’s rate is generally regarded as evidence of adverse impact — is a rule of thumb, not a safe harbour.
A machine learning model is a selection procedure. Nothing in the Uniform Guidelines depends on how the procedure was built.
The federal enforcement posture changed in 2025: AI guidance documents were removed from federal agency websites and an executive order directed agencies to deprioritise disparate-impact liability. Note carefully what that does and does not change. It does not amend Title VII, it does not overrule Griggs, it does not bind courts, and it does not affect private plaintiffs or state fair employment agencies — several of which enforce state analogues independently. The risk moved from regulator to plaintiff; it did not disappear.
The ADA angle is separately underrated. A tool that screens on characteristics correlated with disability — speech patterns, facial expressiveness, response latency, gaps in employment history — raises a screening-out claim and a reasonable accommodation question, and neither is answered by a demographic parity audit.
The vendor can be liable too
The assumption that the employer bears all the risk has been undermined. In litigation against Workday in the Northern District of California, the court allowed claims to proceed against the vendor on an agent theory — that a screening provider performing a traditional employer function on the employer’s behalf can be liable under the anti-discrimination statutes — and in 2025 permitted a nationwide collective action to proceed on the age discrimination claim.
The case had not produced a final merits ruling at this review date and it is one district court. But the theory is now live, and it changes the negotiation: a vendor that can be joined has a reason to give you the validation evidence, the impact data and the indemnity that vendors have historically refused. Ask for all three, and see what to put in the contract.
A programme that would survive scrutiny
- Write down what the tool is selecting for and why each characteristic is job-related. If you cannot articulate the business necessity for a feature before deployment, you will not manage it in litigation.
- Test for adverse impact before use, not after, by sex, race and ethnicity, age and, where you can, disability proxies. Compute impact ratios. Keep the results and the date.
- Search for a less discriminatory alternative and record the search. This is the element most audits omit entirely and it is an element of the legal test, not a nicety.
- Provide an accommodation route that is genuinely available and does not disadvantage the candidate who uses it.
- Keep a human decision-maker with authority to override, and train them on the tool’s limits. See the literacy obligation for what that training has to cover.
- Re-test on your own data at intervals. A vendor audit on the vendor’s population is not evidence about your applicant pool, and the impact you are liable for is the impact in your process.
- Retain the records. Selection data, model versions, thresholds and overrides. Federal record-keeping requirements for selection procedures apply to this data as to any other.
Top comments (0)