9 min read

Patchwork of AI Hiring Regulations Creates Uncertainty

Patchwork of AI Hiring Regulations Creates Uncertainty
Photo by Igor Omilaev / Unsplash

A survey of where we are today

SLN previously reported on the emerging litigation threat arising from the use of AI tools to evaluate employment candidates. These cases involve claims that AI tools that review and classify candidates operate to discriminate against legally protected workers on the basis of factors like age or disability. This is known as the "adverse impact" theory of liability, available under Title VII of the Civil Rights Act of 1964, the Age Discrimination in Employment Act, the Americans with Disabilities Act, and their state equivalents. The doctrine, stated simply, is that an otherwise neutral factor that acts adversely on a protected group can form the basis of employer liability for employment discrimination. Examples of neutral factors are things commonly seen in resumes, like employment dates (age), gaps in employment (disability), and address (race), to name a few.

At the same time, the use of AI in the employment context has come under scrutiny by state and local legislators. As a result, employers that use AI to assess applicants have a growing number of legislatively mandated compliance obligations. The laws are not consistent—a firm hiring candidates based in New York City, Chicago, Los Angeles, and Hartford operates under four sets of rules, enforced by four different bodies.

Laws in effect now

New York City. Local Law 144 has applied since July 2023, and it covers employment agencies by its terms, not just employers. A covered user of an automated employment decision tool must obtain an annual bias audit from an independent third party, post a summary of the results publicly, and give candidates at least ten business days’ notice before using the tool. Penalties run from $500 to $1,500 per day. The law applies even where a human makes the final decision based on an AI-generated score or ranking.

Illinois. HB 3773 took effect January 1, 2026. It amends the Illinois Human Rights Act ("IHRA") to make it a civil rights violation to use AI that discriminates against applicants or employees, and it covers unintentional adverse impact. Employers must give notice when AI is used in a covered employment decision and may not use ZIP codes as a proxy for protected characteristics. The Illinois Artificial Intelligence Video Interview Act, on the books since 2020, separately requires notice, an explanation of the technology, and advance consent before AI analyzes a recorded interview.

California. As usual, Califirnia is in a class by itself. Civil Rights Council regulations under the Fair Employment and Housing Act ("FEHA") took effect October 1, 2025. They prohibit automated decision systems that discriminate on a protected basis, make the presence or absence of bias testing relevant evidence in a discrimination claim, and require four-year retention of automated decision system ("ADS") data. The regulations take effect January 1, 2027, and apply to firms with at least $26.6 million in global revenue. The threshold is indexed—expect it to increase.

The rules cover the use of technology to make decisions about hiring, work assignment, pay, promotion, or termination. The definition is broad enough to potentially catch simple screening filters, not just sophisticated AI.

There is a potential out. If a human actually reviews the tool's output, understands what it means, and has authority to change the result, the regulations do not apply to that decision. However, in practice, that is hard to achieve in real-world recruiting. A single requisition may generate hundreds of machine-ranked applicants, and candidates screened out before a recruiter looks at anything have been rejected without the human involvement the exception requires.

Otherwise, four obligations attach:

A risk assessment before you use the tool. You weigh the privacy risks against the benefits, document the analysis, get an executive to sign an attestation, and file summary information with the state. The first filings are due April 1, 2028. If the risks outweigh the benefits and you cannot fix that, you cannot use the tool.

A notice before you collect the data. It has to explain what the tool does, what information it uses, what it produces, how that affects the decision, and what rights the applicant has.

An opt-out right, with a significant carve-out. Applicants can generally refuse to be evaluated by the tool. But for hiring, work assignment, and pay decisions, you can deny the opt-out if you have confirmed the tool works as intended and does not discriminate. That exception is what makes high-volume screening workable, and it depends entirely on having the validation and bias testing data to back it up.

An explanation on request. Anyone evaluated by the tool can request information about it. The regulations require four things to be disclosed in response: the purpose the tool was used for, a description of its logic, the output, and how that output was used in the decision. Trade secrets are excluded, as is information that would compromise security, fraud prevention, or human safety. How much detail satisfies the logic requirement, and how far the trade secret exclusion reaches, are unresolved. Nothing has been enforced, and no guidance has issued.

The concern: if rejected candidates exercise this right at scale, responding will be a significant operational burden, to say the least. Moreover, the answer has to come from the AI vendors, whose platforms will need to generate compliant responses as part of the service. Whether they will build that in time is an open question. And what about the basic AI providers like OpenAI, Anthropic, or MS Copilot? Will they bother to build in a feature that handles this? In any event, now is the time to ask your vendor, "Will your tool enable my firm to quickly and fully respond to disappointed California job applicants who exercise their right to know how and why the tool rejected them?

The particular danger in California: Most of these laws are enforced by an agency, sometimes with a cure period and no private right of action. California is the exception. The Civil Rights Council regulations operate through the Fair Employment and Housing Act, so a rejected applicant follows the ordinary discrimination path: regulatory complaint, right-to-sue letter, and civil action, opening the door to class claims, jury trials, uncapped compensatory and punitive damages, one-way fee shifting, and no cure period. Anyone familiar with how such litigation works in California will appreciate the level of risk. The irony, of course, is that California is where most AI tools are being created.

Texas. The Texas Responsible Artificial Intelligence Governance Act ("TRAIGA") took effect January 1, 2026, and reaches only intentional AI-based discrimination. There is no adverse impact liability, no audit requirement, and no notice requirement. The attorney general has exclusive enforcement authority and must give a 60-day cure period.

Maryland. Maryland requires written consent before facial recognition is used on an applicant.

Utah. Utah requires disclosure when a person is interacting with generative AI.

Coming laws (expect more)

Connecticut. The Artificial Intelligence Responsibility and Transparency Act phases in starting October 1, 2026. On that date the automated employment decision technology framework takes effect, WARN notices must disclose whether a layoff is related to AI or other technological change, and an amendment to the Fair Employment Practices Act establishes that use of the technology is not a defense to a discrimination claim. Courts and regulators may treat anti-bias testing as a mitigating factor, weighing its quality, recency, scope, and what the employer did about the results. Pre-decision notice and an interactive disclosure mechanism follow on October 1, 2027.

Colorado. The 2024 Colorado AI Act was repealed and replaced before it ever took effect. Its successor, SB 26-189, applies from January 1, 2027, to automated decision-making technology that "materially influences a consequential decision," including hiring, promotion, discipline, and discharge. Just what this means is unclear—the attorney general is directed to adopt rules on or before January 1, 2027, and those rules may shed some light on what "materially influences a consequential decision" means. Covered employers must give pre-use notice, make a post-adverse-outcome disclosure within 30 days, keep three years of records, and provide affected individuals with meaningful human review and a right to correct inaccurate personal data. Waiting on the regulations for clarity.

New York. The AI Labor Information Act has passed both chambers and awaits the governor. It would require covered employers to report annually to the Department of Labor on how their AI use affected hiring, layoffs, hours, and job tasks.

Unsettled laws

Colorado’s attorney general is not required to issue interpretive rules until January 1, 2027, the same day the statute takes effect. Those rules are supposed to clarify the post-adverse-outcome notice requirements and the meaning of "materially influence," which are the two provisions employers most need explained. The state's position is further complicated by litigation. In April, a federal court stayed enforcement in a constitutional challenge brought by xAI and joined by the Justice Department. By its terms the order reaches legislation enacted this session to replace or amend the original act, which includes SB 26-189, and runs until fourteen days after the court rules on a preliminary injunction motion. That motion is not due until 28 days after Colorado finalizes its rulemaking, so the stay will likely outlast the statute's January 1, 2027, effective date. Commentators disagree on whether the order suspends enforcement generally or only as to xAI, and firms should not read it as relief from compliance.

Illinois has a version of the same problem. The Department of Human Rights published proposed notice rules in May, then withdrew them and canceled the public hearing. The statutory obligation to give notice remains in force. What a compliant notice contains has not been established.

The regulatory approaches summarized

The drafting varies, but the underlying approaches fall into a handful of categories.

Notice. The most common requirement. Illinois, Colorado, Connecticut, the California privacy rules, and New York City all require telling candidates the technology is in use. They disagree on timing, content, and method of delivery.

Consent. Limited so far to specific technologies. Recorded video interviews in Illinois and facial recognition in Maryland.

Bias testing. Mandatory and publicly posted in New York City. Elsewhere it is encouraged through evidentiary rules that make testing useful in defense and its absence useful to a plaintiff. In California it does double duty, since testing is also what lets an employer refuse an applicant's opt-out.

Candidate rights. This is new in California and different from the rest. The other laws give the state a rule to enforce. California gives the individual applicant something to exercise: the right to opt out of being evaluated and the right to demand an explanation afterward.

Explanation. Arriving in 2027 in both California and Colorado, but structured differently. Colorado requires the employer to push out an explanation after an adverse decision. California waits for the candidate to ask.

Human review. Colorado requires it as a right, and California's pending SB 947 would require it for discipline and termination.

Assessment and documentation. California requires a documented risk assessment, executive attestation, and a state filing before a covered tool is used. Colorado requires developers to hand deployers documentation on intended uses, training data, and known limitations. This is the category most dependent on vendor cooperation.

Recordkeeping. Four years in California, three in Colorado, and four in Illinois, as proposed.

Will the federal government fix this mess?

A federal effort to pass an overriding bill that preempts this hodgepodge has been running alongside the state activity for more than a year, but Congress has twice declined to act. A provision in the "One Big Beautiful Bill Act" would have preempted state AI regulation for ten years, and the Senate voted 99-1 to strip it. Congress then declined to enact a similar moratorium through the National Defense Authorization Act. A bipartisan group of more than 30 state attorneys general publicly opposed broad preemption.

The administration has turned to executive action. Executive Order 14365, signed December 11, 2025, directs the Attorney General to create an AI Litigation Task Force whose sole responsibility is challenging state AI laws, orders Commerce to publish an evaluation of "onerous" state laws, instructs the FCC to consider a federal reporting and disclosure standard that would supersede conflicting state law, directs the FTC to issue a policy statement on when state laws requiring alterations to AI outputs are preempted under Section 5 of the FTC Act, and conditions certain federal broadband funds on states refraining from restrictive AI laws. It also charges White House advisors with drafting preemption legislation, carving out child safety, data center infrastructure, and state government procurement. Employment is not among the carve-outs. The White House framework released in March recommended that Congress preempt broadly while preserving state authority over child protection, consumer fraud, zoning, and state procurement. Akin Gump’s employment group read that framework as recommending preemption of state employment-related AI requirements specifically.

Commentators are skeptical that the executive action displaces state law without action by Congress. Ropes & Gray’s analysis concludes that the executive order is neither a statute nor a regulation and therefore lacks preemptive force on its own, and the order’s own acknowledgment that no federal regulatory framework exists complicates the argument that state laws conflict with federal law. The firm also notes that Congress’s two rejections of preemption language could be read as evidence that Congress does not intend to foreclose state regulation.

Reuters legal industry coverage in August gave companies the same advice, noting that without an act of Congress expressly preempting state AI law, executive branch action alone is unlikely to override state regimes already in effect.

Bottom line: Bottom line: State and local AI regulation in employment is complicated, burdensome, and not likely to go away any time soon. The most restrictive states will set the standard for all because in this day of remote employment, no recruiter can predict where the applicant will live. Will your AI tool be compliant in 2027? Can it tell a rejected California applicant why it rejected them? Ask your vendor now, because 2027 will be here soon.